Cisco APIC Layer 2 Networking Configuration Guide, Release 3.x and Earlier FirstPublished:2017-04-11 AmericasHeadquarters CiscoSystems,Inc. 170WestTasmanDrive SanJose,CA95134-1706 USA http://www.cisco.com Tel:408526-4000 800553-NETS(6387) Fax:408527-0883 ©2017–2022CiscoSystems,Inc.Allrightsreserved. Trademarks THESPECIFICATIONSANDINFORMATIONREGARDINGTHEPRODUCTSREFERENCEDINTHIS DOCUMENTATIONARESUBJECTTOCHANGEWITHOUTNOTICE.EXCEPTASMAYOTHERWISE BEAGREEDBYCISCOINWRITING,ALLSTATEMENTS,INFORMATION,AND RECOMMENDATIONSINTHISDOCUMENTATIONAREPRESENTEDWITHOUTWARRANTYOF ANYKIND,EXPRESSORIMPLIED. TheCiscoEndUserLicenseAgreementandanysupplementallicensetermsgovernyouruseofanyCisco software,includingthisproductdocumentation,andarelocatedat: http://www.cisco.com/go/softwareterms.Ciscoproductwarrantyinformationisavailableat http://www.cisco.com/go/warranty.USFederalCommunicationsCommissionNoticesarefoundhere http://www.cisco.com/c/en/us/products/us-fcc-notice.html. INNOEVENTSHALLCISCOORITSSUPPLIERSBELIABLEFORANYINDIRECT,SPECIAL, CONSEQUENTIAL,ORINCIDENTALDAMAGES,INCLUDING,WITHOUTLIMITATION,LOST PROFITSORLOSSORDAMAGETODATAARISINGOUTOFTHEUSEORINABILITYTOUSE THISMANUAL,EVENIFCISCOORITSSUPPLIERSHAVEBEENADVISEDOFTHEPOSSIBILITY OFSUCHDAMAGES. Anyproductsandfeaturesdescribedhereinasindevelopmentoravailableatafuturedateremaininvarying stagesofdevelopmentandwillbeofferedonawhen-andif-availablebasis.Anysuchproductorfeature roadmapsaresubjecttochangeatthesolediscretionofCiscoandCiscowillhavenoliabilityfordelayinthe deliveryorfailuretodeliveranyproductsorfeatureroadmapitemsthatmaybesetforthinthisdocument. AnyInternetProtocol(IP)addressesandphonenumbersusedinthisdocumentarenotintendedtobeactual addressesandphonenumbers.Anyexamples,commanddisplayoutput,networktopologydiagrams,and otherfiguresincludedinthedocumentareshownforillustrativepurposesonly.AnyuseofactualIPaddresses orphonenumbersinillustrativecontentisunintentionalandcoincidental. Thedocumentationsetforthisproductstrivestousebias-freelanguage.Forthepurposesofthisdocumentation set,bias-freeisdefinedaslanguagethatdoesnotimplydiscriminationbasedonage,disability,gender,racial identity,ethnicidentity,sexualorientation,socioeconomicstatus,andintersectionality.Exceptionsmaybe presentinthedocumentationduetolanguagethatishardcodedintheuserinterfacesoftheproductsoftware, languageusedbasedonRFPdocumentation,orlanguagethatisusedbyareferencedthird-partyproduct. CiscoandtheCiscologoaretrademarksorregisteredtrademarksofCiscoand/oritsaffiliatesintheU.S.and othercountries.ToviewalistofCiscotrademarks,gotothisURL:www.cisco.comgotrademarks.Third-party trademarksmentionedarethepropertyoftheirrespectiveowners.Theuseofthewordpartnerdoesnotimply apartnershiprelationshipbetweenCiscoandanyothercompany.(1721R) CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier iii Trademarks Trademarks CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier iv CONTEN TS PREFACE Trademarks iii CHAPTER 1 NewandChanged 1 NewandChangedInformation 1 CHAPTER 2 CiscoACIForwarding 9 ACIFabricOptimizesModernDataCenterTrafficFlows 9 VXLANinACI 10 Layer3VNIDsFacilitateTransportingInter-subnetTenantTraffic 12 TransmissionofSTPBPDU 13 CHAPTER 3 PrerequisitesforConfiguringLayer2Networks 15 Layer2Prerequisites 15 CHAPTER 4 NetworkingDomains 17 NetworkingDomains 17 RelatedDocuments 18 BridgeDomains 18 AboutBridgeDomains 18 VMMDomains 18 VirtualMachineManagerDomainMainComponents 18 VirtualMachineManagerDomains 19 ConfiguringPhysicalDomains 19 ConfiguringaPhysicalDomain 19 ConfiguringaPhysicalDomainUsingtheRESTAPI 20 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier v Contents CHAPTER 5 Bridging 23 BridgedInterfacetoanExternalRouter 23 BridgeDomainsandSubnets 24 BridgeDomainOptions 27 CreatingaTenant,VRF,andBridgeDomainUsingtheGUI 28 CreatingaTenant,VRF,andBridgeDomainUsingtheNX-OSStyleCLI 29 CreatingaTenant,VRF,andBridgeDomainUsingtheRESTAPI 30 ConfiguringanEnforcedBridgeDomain 31 ConfiguringanEnforcedBridgeDomainUsingtheNX-OSStyleCLI 32 ConfiguringanEnforcedBridgeDomainUsingtheRESTAPI 33 ConfiguringFloodinEncapsulationforAllProtocolsandProxyARPAcrossEncapsulations 34 CHAPTER 6 EPGs 39 AboutEndpointGroups 39 EndpointGroups 39 AccessPoliciesAutomateAssigningVLANstoEPGs 41 PerPortVLAN 42 VLANGuidelinesforEPGsDeployedonvPCs 44 DeployinganEPGonaSpecificPort 45 DeployinganEPGonaSpecificNodeorPortUsingtheGUI 45 DeployinganEPGonaSpecificPortwithAPICUsingtheNX-OSStyleCLI 46 DeployinganEPGonaSpecificPortwithAPICUsingtheRESTAPI 47 CreatingDomains,AttachEntityProfiles,andVLANstoDeployanEPGonaSpecificPort 48 CreatingDomains,AttachEntityProfiles,andVLANstoDeployanEPGonaSpecificPort 48 CreatingDomains,andVLANStoDeployanEPGonaSpecificPortUsingtheGUI 48 CreatingAEP,Domains,andVLANstoDeployanEPGonaSpecificPortUsingtheNX-OSStyle CLI 49 CreatingAEP,Domains,andVLANstoDeployanEPGonaSpecificPortUsingtheRESTAPI 50 ValidatingOverlappingVLANs 52 ValidatingOverlappingVLANsUsingtheGUI 52 ValidatingOverlappingVLANsUsingtheRESTAPI 52 DeployingEPGstoMultipleInterfacesThroughAttachedEntityProfiles 53 DeployinganApplicationEPGthroughanAEPorInterfacePolicyGrouptoMultiplePorts 53 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier vi Contents DeployinganEPGthroughanAEPtoMultipleInterfacesUsingtheAPICGUI 53 DeployinganEPGthroughanInterfacePolicyGrouptoMultipleInterfacesUsingtheNX-OSStyle CLI 54 DeployinganEPGthroughanAEPtoMultipleInterfacesUsingtheRESTAPI 55 Intra-EPGIsolation 57 Intra-EPGEndpointIsolation 57 Intra-EPGIsolationforBareMetalServers 57 Intra-EPGIsolationforBareMetalServers 57 ConfiguringIntra-EPGIsolationforBareMetalServersUsingtheGUI 58 ConfiguringIntra-EPGIsolationforBareMetalServersUsingtheNX-OSStyleCLI 59 ConfiguringIntra-EPGIsolationforBareMetalServersUsingtheRESTAPI 61 Intra-EPGIsolationforVMWarevDS 61 Intra-EPGIsolationforVMwareVDSorMicrosoftHyper-VVirtualSwitch 61 ConfiguringIntra-EPGIsolationforVMwareVDSorMicrosoftHyper-VVirtualSwitchusing theGUI 63 ConfiguringIntra-EPGIsolationforVMwareVDSorMicrosoftHyper-VVirtualSwitchusing theNX-OSStyleCLI 64 ConfiguringIntra-EPGIsolationforVMwareVDSorMicrosoftHyper-VVirtualSwitchusing theRESTAPI 65 Intra-EPGIsolationforAVS 66 Intra-EPGIsolationEnforcementforCiscoAVS 66 ConfiguringIntra-EPGIsolationforCiscoAVSUsingtheGUI 67 ConfiguringIntra-EPGIsolationforCiscoAVSUsingtheNX-OSStyleCLI 68 ConfiguringIntra-EPGIsolationforCiscoAVSUsingtheRESTAPI 68 ChoosingStatisticstoViewforIsolatedEndpointsonCiscoAVS 69 ViewingStatisticsforIsolatedEndpointsonCiscoAVS 69 CHAPTER 7 AccessInterfaces 71 PhysicalPorts 71 ConfiguringLeafSwitchPhysicalPortsUsingPolicyAssociation 71 ConfiguringLeafSwitchPhysicalPortsUsingPortAssociation 73 ConfiguringPhysicalPortsinLeafNodesandFEXDevicesUsingtheNX-OSCLI 73 PortCloning 76 CloningPortConfigurations 76 CloningaConfiguredLeafSwitchPortUsingtheAPICGUI 77 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier vii Contents PortChannels 77 PC/vPCHostLoadBalancingAlgorithms 77 ACILeafSwitchPortChannelConfigurationUsingtheGUI 78 ConfiguringPortChannelsinLeafNodesandFEXDevicesUsingtheNX-OSCLI 80 ConfiguringTwoPortChannelsAppliedtoMultipleSwitchesUsingtheRESTAPI 86 VirtualPortChannels 88 AboutVirtualPortChannelsinCiscoACI 88 ACIVirtualPortChannelWorkflow 89 VirtualPortChannelUseCases 91 vPCWiththeSameLeafSwitchInterfacesAcrossTwoLeafSwitchesWithCombinedProfiles 91 vPCWiththeSameLeafSwitchInterfacesAcrossTwoLeafSwitcheswithIndividualProfiles 93 vPCWithDifferentLeafSwitchInterfacesAcrossTwoLeafSwitchsWithIndividualProfiles 95 DefiningvPCSwitchPairsUsingtheGUI 97 ACILeafSwitchVirtualPortChannelConfigurationUsingtheGUI 97 ConfiguringVirtualPortChannelsinLeafNodesandFEXDevicesUsingtheNX-OSCLI 99 ConfiguringaSingleVirtualPortChannelAcrossTwoSwitchesUsingtheRESTAPI 104 ConfiguringaVirtualPortChannelonSelectedPortBlocksofTwoSwitchesUsingtheREST API 105 VirtualPortChannelMigration-MigrationofNodesfromaFirst-GenerationSwitchtoa Second-GenerationSwitch 106 ReflectiveRelay 108 ReflectiveRelay(802.1Qbg) 108 EnablingReflectiveRelayUsingtheAdvancedGUI 108 EnablingReflectiveRelayUsingtheNX-OSCLI 109 EnablingReflectiveRelayUsingtheRESTAPI 110 FEXInterfaces 111 ConfiguringPort,PC,andvPCConnectionstoFEXDevices 111 ACIFEXGuidelines 111 FEXVirtualPortChannels 112 ConfiguringaBasicFEXConnectionUsingtheGUI 114 ConfiguringFEXPortChannelConnectionsUsingtheGUI 116 ConfiguringFEXvPCConnectionsUsingtheGUI 118 ConfiguringanFEXVPCPolicyUsingtheRESTAPI 120 ConfiguringFEXConnectionsUsingProfileswiththeNX-OSStyleCLI 123 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier viii Contents ConfiguringPortProfilestoChangePortsfromUplinktoDownlinkorDownlinktoUplink 124 ConfiguringPortProfiles 124 PortProfileConfigurationSummary 126 ConfiguringaPortProfileUsingtheGUI 128 ConfiguringaPortProfileUsingtheNX-OSStyleCLI 129 ConfiguringaPortProfileUsingtheRESTAPI 130 VerifyingPortProfileConfigurationandConversionUsingtheNX-OSStyleCLI 131 CHAPTER 8 FCoEConnections 133 SupportingFibreChanneloverEthernetTrafficontheACIFabric 133 FibreChanneloverEthernetGuidelinesandLimitations 135 FibreChanneloverEthernetSupportedHardware 135 ConfiguringFCoEUsingtheAPICGUI 136 FCoEGUIConfiguration 136 FCoEPolicy,Profile,andDomainConfigurations 136 DeployingFCoEvFCPortsUsingtheAPICGUI 139 DeployingEPGAccesstovFCPortsUsingtheAPICGUI 145 DeployingtheEPGtoSupporttheFCoEInitiationProtocol 148 UndeployingFCoEConnectivityUsingtheAPICGUI 150 ConfiguringFCoEUsingtheNX_OSStyleCLI 151 FCoENX-OSStyleCLIConfiguration 151 ConfiguringFCoEConnectivityWithoutPoliciesorProfilesUsingtheNX-OSStyleCLI 151 ConfiguringFCoEConnectivityWithPoliciesandProfilesUsingtheNX-OSStyleCLI 155 ConfiguringFCoEOverFEXUsingNX-OSStyleCLI 158 VerifyingFCoEConfigurationUsingtheNX-OSStyleCLI 160 UndeployingFCoEElementsUsingtheNX-OSStyleCLI 161 ConfiguringFCoEUsingtheRESTAPI 162 ConfiguringFCoEConnectivityUsingtheRESTAPI 162 ConfiguringFCoEOverFEXUsingRESTAPI 166 ConfiguringanFCoEvPCUsingtheRESTAPI 170 UndeployingFCoEConnectivitythroughtheRESTAPIorSDK 172 SANBootwithvPC 177 ConfiguringSANBootwithvPCUsingtheGUI 178 SANBootwithvPCConfigurationUsingtheCLI 181 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier ix Contents CHAPTER 9 FibreChannelNPV 183 FibreChannelConnectivityOverview 183 NPVTrafficManagement 184 AutomaticUplinkSelection 185 TrafficMaps 185 DisruptiveAutoLoadBalancingofServerLoginsacrossNPLinks 185 FCNPVTrafficManagementGuidelines 186 SANA/BSeparation 186 SANPortChannels 187 FibreChannelN-PortVirtualizationGuidelinesandLimitations 188 FibreChannelN-PortVirtualizationSupportedHardware 189 FibreChannelN-PortVirtualizationInteroperability 189 FibreChannelNPVGUIConfiguration 190 ConfiguringaNativeFibreChannelPortProfileUsingtheGUI 190 ConfiguringaNativeFCPortChannelProfileUsingtheGUI 192 DeployingFibreChannelPorts 193 ConfiguringaTrafficMapforaFibreChannelPort 195 FibreChannelNPVNX-OS-StyleCLIConfiguration 196 ConfiguringFibreChannelInterfacesUsingtheCLI 196 ConfiguringFibreChannelNPVPoliciesUsingtheCLI 198 ConfiguringanNPVTrafficMapUsingtheCLI 199 FibreChannelNPVRESTAPIConfiguration 200 ConfiguringFCConnectivityUsingtheRESTAPI 200 CHAPTER 10 802.1QTunnels 205 AboutACI802.1QTunnels 205 Configuring802.1QTunnelsUsingtheGUI 207 Configuring802.1QTunnelInterfacesUsingtheAPICGUI 207 Configuring802.1QTunnelsUsingtheNX-OSStyleCLI 209 Configuring802.1QTunnelsUsingtheNX-OSStyleCLI 209 Example:Configuringan802.1QTunnelUsingPortswiththeNX-OSStyleCLI 210 Example:Configuringan802.1QTunnelUsingPort-ChannelswiththeNX-OSStyleCLI 211 Example:Configuringan802.1QTunnelUsingVirtualPort-ChannelswiththeNX-OSStyleCLI 212 CiscoAPICLayer2NetworkingConfigurationGuide,Release3.xandEarlier x
Description: