04-06-2024 03:17 AM
Can someone please help this is very urgent. I have this configuration in the ACI where all the Subnets reside in 1 BD and 1 VRF as shown in the diagram. Additional to this I have configured the L2OUT adding the subnet again and contracts respectively. All the configuration seems ok, have applied the contracts also properly but the problem is that I can communicate from PC(Vlan110) to the Server(vlan111) but not vice versa.
Solved! Go to Solution.
04-06-2024 01:34 PM - edited 04-06-2024 01:49 PM
Hi @niceinfotech ,
First, some tips. Trust me, there is a full answer below.
RedNectar's Forum Tips:
Po
This means you pictures are actually SEEN (a) in the email that gets sent to subscribers and (b) anyone who looks at this post in the future. Adding pictures as attachments... puts your submission into the TL;DR category.
This will give you access to the paragraph formatting drop down
</end of RedNectar's Forum Tips>
Now to your question - and let's put the diagrams in to make it readable:
Can someone please help this is very urgent. I have this configuration in the ACI where all the Subnets reside in 1 BD and 1 VRF as shown in the diagram.
Additional to this I have configured the L2OUT adding the subnet again and contracts respectively. .
Let's start with the L2Outs.
My advice is NEVER use L2Outs, use Application EPGs instead. L2Outs are an abomination and do NOTHING to enhance ACI. More detail in this answer I gave previously
Also, adding Subnets to the L2Out (or Application EPG when you migrate your config) is not necessary and only confuses the matter when you have Subnets on the BD. You either put the subnet(s) on the BD or the EPG (or L2Out) to keep things simple and avoid confusion. The only time you NEED to put a subnet on an EPG/L2Out is if it is the PROVIDER of a contract that is consumed by an EPG/L2out IN ANOTHER VRF.
Since you have only one VRF, just stick to putting the IP addresses on the BD.
All the configuration seems ok, have applied the contracts also properly but the problem is that I can communicate from PC(Vlan110) to the Server(vlan111) but not vice versa
You SAY you have "applied the contracts", but you have not shown any evidence of the contracts.
HOWEVER, this is of no consequence, because you have set the VRF Policy Control Enforcement to Unenforced.
So. What now?
This is what I advise:
04-06-2024 03:21 AM
04-06-2024 01:34 PM - edited 04-06-2024 01:49 PM
Hi @niceinfotech ,
First, some tips. Trust me, there is a full answer below.
RedNectar's Forum Tips:
Po
This means you pictures are actually SEEN (a) in the email that gets sent to subscribers and (b) anyone who looks at this post in the future. Adding pictures as attachments... puts your submission into the TL;DR category.
This will give you access to the paragraph formatting drop down
</end of RedNectar's Forum Tips>
Now to your question - and let's put the diagrams in to make it readable:
Can someone please help this is very urgent. I have this configuration in the ACI where all the Subnets reside in 1 BD and 1 VRF as shown in the diagram.
Additional to this I have configured the L2OUT adding the subnet again and contracts respectively. .
Let's start with the L2Outs.
My advice is NEVER use L2Outs, use Application EPGs instead. L2Outs are an abomination and do NOTHING to enhance ACI. More detail in this answer I gave previously
Also, adding Subnets to the L2Out (or Application EPG when you migrate your config) is not necessary and only confuses the matter when you have Subnets on the BD. You either put the subnet(s) on the BD or the EPG (or L2Out) to keep things simple and avoid confusion. The only time you NEED to put a subnet on an EPG/L2Out is if it is the PROVIDER of a contract that is consumed by an EPG/L2out IN ANOTHER VRF.
Since you have only one VRF, just stick to putting the IP addresses on the BD.
All the configuration seems ok, have applied the contracts also properly but the problem is that I can communicate from PC(Vlan110) to the Server(vlan111) but not vice versa
You SAY you have "applied the contracts", but you have not shown any evidence of the contracts.
HOWEVER, this is of no consequence, because you have set the VRF Policy Control Enforcement to Unenforced.
So. What now?
This is what I advise:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide