Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,
We have 2 bare-metal servers running DCNM 11.5(1) in HA for manaiging our VXLAN Fabrics and wish to upgrade them to 11.5(4).
Reading the upgrade guide, I assume I should use the Linux Federation through Silent Installation process.
If so,
1. How ...
Hi Folks,
What is the best way to create an ACL for a VLAN to restrict some host connectivity in a VXLAN Fabric please using DCNM?
DCNM has been used to create the Fabric and uses / applies profiles for the various VLANs.
Do I have to use the switch ...
Hello,
We are deploying a VXLAN Fabric at 2 Sites and will use Multisite to connect them for streched VLANs.
The plan is to use virtual appliances for a distributed deployment with 2 Master nodes at site A and 1 Master and 1 Standby at site B. We wil...
Hi,
I have a VXLAN EVPN Fabric and have successfully peered with an external BGP router and exchanged routes.
I now wish to peer directly with a pair of OSPF routers and redistribute specifc prefixes to them. There are about 20 discontiguous prefixes...
Hi, Is it possible / recommended to have two DCNM physical appliances in native HA mode with the devices connected over two EVPN connected VXLAN Fabrics? Both Fabrics will have latency of <20ms latency between them.I was hoping to configure the first...
Thanks for your replies.
So I have no choice but to use configuration profiles and if I need to add the access-group to the VLAN, the following switch freeform configuration with just the addition of the ACL should work, leaving all current configura...
Thanks for your quick response.
To un-apply a profile, is it simply no apply profile XXXX ?
For example, the switch freeform configuration will look something like this - (Actual ACL FUEL-DENY omitted in the example)
no apply profile PRODUCTION-VL321...
Thanks David, but what I really need to know is if the following configuration would work when peering externally from the VXLAN Fabric using OSPF.
router ospf 100vrf prodredistribute bgp 65501 route-map BGP-TO-OSPF
route-map BGP-TO-OSPF permit 10mat...
Thanks for your reply.For this situation, we actually only need OTV between DC-3 (new) to DC-1 where the new p2p circuits terminate.I forgot to mention that the ASR's are "on a stick" and not in-line.If a fully meshed solution was required, but would...
Hi Rick,So for the late reply.Yes, changing the master key resolved the issue. The customer wasn't sure what they were so I simply removed the keys and created new ones on both sides.The Tunnel came straight up and all traffic encrypted across it.Th...