04-27-2016 01:47 PM - edited 03-01-2019 04:57 AM
I have a service graph deployed, everything looks good except I had the ACL applied on the wrong interface. Can I update the config from ACI or do I have to re-apply the Service Graph template?
Thanks,
Bryan
Solved! Go to Solution.
04-28-2016 07:47 AM
When you apply a service graph, the parameters of the service graph as applied, show up under the Provider EPG. They should be under the Provider EPG in a folder called L4-7 parameters. Under this folder you should be able to edit the parameters of the service graph and specifically move the ACL from the internal interface to the external interface.
I've attached a screenshot of where the folder is, you should be able to click the pencil icon and change the parameters, and which interface that ACL gets applied to.
04-27-2016 02:04 PM
Hello Bryan!
You should be able to go to the L4-7 Parameter folder under the provider for the contract where the service graph is attached and adjust which interface the ACL is configured. After adjusting the parameters, ACI will validate and update the L4-7 device.
Hopefully that helps. let me know if you need more information.
04-27-2016 02:11 PM
Not sure what folder you mean. The problem is my ASAv template had the acl on the internal interface. My provider is on the internal side, so I need to move the ACL to the external interface. I could always redeploy and switch consumer/provider but to me the ACL should be on the external side.
04-28-2016 07:47 AM
When you apply a service graph, the parameters of the service graph as applied, show up under the Provider EPG. They should be under the Provider EPG in a folder called L4-7 parameters. Under this folder you should be able to edit the parameters of the service graph and specifically move the ACL from the internal interface to the external interface.
I've attached a screenshot of where the folder is, you should be able to click the pencil icon and change the parameters, and which interface that ACL gets applied to.
04-28-2016 07:54 AM
Awesome, that works! I have also noticed that since I did this exercise 5 times some of the old parameters are still here even though I have deleted the previous graph templates. Any idea how to clean this up easily? Do I need to manually delete them all?
04-28-2016 08:06 AM
When you apply the Service Graph from a template (right clicking the template and applying the graph) there also should be a 'Remove Related Objects of Graph Template' button. Unfortunately if the template is already deleted, that option is not accessible, and then there's no easy way in the GUI to delete the related objects. The other way would be to go in using the API and delete them that way, which can be easier if you are familiar with how to do that.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide