cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
158
Views
0
Helpful
2
Replies

domain network group policy

tdubb123
Level 1
Level 1

Is a domain network group policy necessary for a domain profile on the FIs? I have vlan policy that has tons of vlans with allow on uplinks enabled and the domain ethernet network group policy seems to be causing issues

2 Replies 2

tdubb123
Level 1
Level 1

any idea

Sandeep Kumar
Cisco Employee
Cisco Employee
I am assuming you are referring to Ethernet Network Group policy. 

In VLAN Policy, when we add VLAN's, we have a toggle switch: "Auto Allow On Uplinks"
 
We have two uplink design options:
Option-1: Disjoint Layer 2 Setup
- We should disable "Auto Allow On Uplinks" on all the VLANs.
- We need a separate "Ethernet Network Group" policy for each uplink.
- We also need "Ethernet Network Group" policies for Server vNICs

Option-2: No Disjoint Layer 2 Setup
- If you don't have a Disjoint Layer 2 Setup and have no intentions of doing it in the future, we should keep this option enabled.
- This allows the VLANs on all the uplinks without configuring an "Ethernet Network Group" Policy.
- In this case, we don't need an "Ethernet Network Group" Policy for Uplinks.
- We still need "Ethernet Network Group" policy for Server vNICs