Professional Documents
Culture Documents
Brkaci 2300
Brkaci 2300
•
•
•
•
VM# VM# VM#
•
•
•
•
•
•
•
•
•
• •
ID ID
STAT STAT
UCS 5108
!
SLOT 1 ! 2 ! ! Reset Console 1 ! 2 ! ! Reset Console
SLOT
1 2
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
SLOT SLOT
3 1 ! 2 ! ! Reset Console 1 ! 2 ! ! Reset Console 4
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
SLOT
1 2 SLOT
1 2 ! ! ! Reset Console
5 ! ! ! Reset Console 6
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
•
•
•
•
•
•
APIC
Isolated PVLANs
vmkernel
ports
VM VM VM
AVE
Outside trunk
Inside trunk for traffic to/from the ACI fabric
configured in Promiscuous Mode with Configured with infra VLAN or APIC
Primary and Secondary VLANs VLAN pool depending upon AVE
mode (VXLAN/VLAN)
External Port-group can be
backed by VLAN Pool or ACI
Infra VLAN
VM sends traffic in
Internal AVE Port-group Secondary
is Promiscuous Trunk Isolated VLAN
Outer L2 header
has infra VLAN tag
Internal VLAN Pool -
locally significant
•
•
Each VTEP is linked to
• a single active VMNIC
(other is standby)
•
Traffic between local
VMs and AVE is evenly
• split between 2 vNICs
•
•
•
•
•
• 𝜇
𝜇 𝜇 𝜇
𝜇
𝜇
• 𝜇
•
•
•
•
•
• •
•
•
• •
• •
• •
• •
•
•
•
•
•
EPG EPG
Contract
Web App
VDS
Web App
VDS
Web App
APIC automatically
provisions port-group
and attaches vNIC
*Service Policy mode/Service Manager mode only
•
•
kind: NetworkPolicy
apiVersion: extensions/v1beta1
• metadata:
name: allow-orange-to-blue-same-ns
spec:
• podSelector:
matchLabels:
type: blue
ingress:
- from:
- podSelector:
matchLabels:
type: red
•
•
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny
spec: podSelector: {}
policyTypes:
- Ingress
- Egress
•
• ACI is the best
•
NSXv Mgr NSXv Ctrl
HW VTEP
V
XLA
NOv
er
lay HW VTEP
Network
BM
Virtualization ToR ToR ToR ToR
VXLAN
ESXi ESXi ESXi
Network
Services VPN NAT SLB Perimeter Firewall
Security
+ Ecosystem Partners
Web HTTPS App 3306 DB
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
o
•
o
•
VM# VM# VM# VM# VM# VM#
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
Inter Pod
Network
L3 Pod 1 Pod 2
L3
Out Out
GW GW GW GW GW GW GW GW GW GW
APIC Cluster
vCenter
•
•
•
•
•
•
Inter Site
Network
L3 Site 1 Site 2
L3
Out Out
GW GW GW GW GW GW GW GW GW GW
vCenter vCenter
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•
•