11-20-2017 09:19 AM - edited 03-01-2019 05:22 AM
Hi
I now have a bit of a problem with something that was working last week but is not working now. I am now unable to connect to any of our VMs. I have removed all related EPGs, BDs and VMM domain and recreated everything from scratch with no effect. I feel there is something I'm missing somewhere or I've come across some bug.
We have an EPG with a VMM domain asociation. I have added the subnet in the EPG. I have added provide and consume contracts using the common/default for both.
From outside ACI, I can ping the EPG gateway IP but I cannot ping the VMs in the EPG. The VMs in the EPG can ping each other but cannot ping their default gateway (i.e. the EPG subnet IP).
From the VM i get the message
Reply from X.X.X.X: Destination host unreachable (where X.X.X.X is the IP of the VM)
On the BD, ARP flooding is disable, with Hardware Proxy set. I know the VRF is routing, as there are other EPGs to physical devices working fine. On the EPG, Operational tab, I see the VMs listed as the learned endpoints.
On the contracts tab, I do not see any traffic, so I'm wondering if a contract/acl has got messed up somewhere. Can anyone suggest any troubleshooting I can check?
For info, we have ACI v.2.3(1f) and VMWare 6.5.
Thanks in advance
Roy
Solved! Go to Solution.
11-21-2017 09:19 AM
Roy,
The resolution Immediacy of both "Immediate" and "On Demand" are similar in that they both require some neighbor relation in conjunction with Access Policies to determine:
This is information is highlight in the document I sent over previously:
With that said, can you clarify the following:
-Gabriel
11-20-2017 09:50 AM
Roy Smith,
If the Endpoints are unable to reach the Gateway programmed in ACI, then that likely means that there is some config missing/issue with the VMM domain to EPG assignment. This may be causing the VLAN to not get programmed on the Front Panel interface so that the EP can be classified/let into the fabric/reach the gateway.
Whether or not the VLAN gets programmed depends on the Access policies in conjunction with the Resolution immediacy set on the VMM Domain to EPG assignment:
The other point to note would be to check if you see any faults on the EPG or within the VMM domain itself. Those may help pinpoint the issue.
-Gabriel
11-21-2017 02:24 AM
Hi Gabriel
I am not seeing any faults anywhere within EPG or anywhere in the fabric.
I have tried setting deployment and resolution immediacy to immediate and On Demand, with no difference. I have even removed the VMM association and added it back, again with no difference.
On the Leafs connected to our UCS devices, when I look at the zoning-rules, I can see the contracts being shown, so I assume this means they are being applied to the switches?
Thanks
Roy
11-21-2017 09:19 AM
Roy,
The resolution Immediacy of both "Immediate" and "On Demand" are similar in that they both require some neighbor relation in conjunction with Access Policies to determine:
This is information is highlight in the document I sent over previously:
With that said, can you clarify the following:
-Gabriel
11-23-2017 04:47 AM
Gabriel
I went through your troubleshooting steps. When I logged in to the CLI on our UCS FI devices, I noticed the vlans were not being shown on the vethernet interfaces. I queried this with our Server guys and it transpires that one of them had been modifying various service templates, including the vnic templates. Therefore the vlan pool assigned for the VMs was not being trunked to the ESX servers.
So, once we added the vlans back on the vnic templates, everything started to work again.
Fortunately, for them, we do not have live VMs running yet! Although all this work is in preparation for the first live VMs getting set up next week.
Thanks for the help.
Roy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide