Download as pdf or txt
Download as pdf or txt
You are on page 1of 93




VM# VM# VM#

VM# VM# VM#


• VM# VM# VM#

VM# VM# VM#













• •

#fabric 101 show cdp nei det



Device ID:ucs-02-B(SSI161107TL)

System Name: ucs-02-BInterface address(es):


IPv4 Address: 10.52.249.6

Platform: UCS-FI-6248UP, Capabilities: Switch


IGMP Filtering Supports-STP-Dispute Interface:

Ethernet1/22, Port ID (outgoing port):


Ethernet1/22

CISCO UCS 6248UP 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 CISCO UCS 6248UP 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32

ID ID

STAT STAT

UCS B230 M1/M2 UCS B230 M1/M2

UCS 5108

!
SLOT 1 ! 2 ! ! Reset Console 1 ! 2 ! ! Reset Console
SLOT
1 2
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA

UCS B230 M1/M2 UCS B230 M1/M2

SLOT SLOT
3 1 ! 2 ! ! Reset Console 1 ! 2 ! ! Reset Console 4

A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA

UCS B230 M1/M2


UCS B230 M1/M2

SLOT
1 2 SLOT
1 2 ! ! ! Reset Console
5 ! ! ! Reset Console 6

A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA

UCS B230 M1/M2


UCS B230 M1/M2

SLOT 1 ! 2 ! ! Reset Console SLOT


7 1 ! 2 ! ! Reset Console 8
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA
A03-D0100SSD-LH
>> 100GB SSD SATA A03-D0100SSD-LH
>> 100GB SSD SATA

OK FAIL OK FAIL OK FAIL OK FAIL








APIC

Also valid for traditional switch


Port-groups mapped to Isolated
PVLAN based on EPG configuration vmkernel port i/o (management,
forcing inter-VM E-W traffic via AVE Physical NICs
vMotion, NFS, etc) does not transit
AVE
VDS

Isolated PVLANs

vmkernel
ports
VM VM VM
AVE

Outside trunk
Inside trunk for traffic to/from the ACI fabric
configured in Promiscuous Mode with Configured with infra VLAN or APIC
Primary and Secondary VLANs VLAN pool depending upon AVE
mode (VXLAN/VLAN)
External Port-group can be
backed by VLAN Pool or ACI
Infra VLAN

VM sends traffic in
Internal AVE Port-group Secondary
is Promiscuous Trunk Isolated VLAN
Outer L2 header
has infra VLAN tag
Internal VLAN Pool -
locally significant

external VLAN Pool –


VLAN tag on the wire



Each VTEP is linked to
• a single active VMNIC
(other is standby)


Traffic between local
VMs and AVE is evenly
• split between 2 vNICs






• 𝜇

VM# VM# VM# VM# VM# VM# VM# VM# VM#

𝜇 𝜇 𝜇

VM# VM# VM# VM# VM# VM# VM# VM# VM#

𝜇
𝜇
• 𝜇

VM# VM# VM#


𝜇




• •


• •
• •
• •
• •




EPG EPG
Contract
Web App

VDS
Web App

*Service Policy mode/Service Manager mode only


EPG EPG
Contract
EPG
Web EPG
App
Contract
EPG
Web EPG
App
Contract
Web App

Multiple SRC and


DEST EPGs can use
the same devices

VDS
Web App

APIC automatically
provisions port-group
and attaches vNIC
*Service Policy mode/Service Manager mode only


kind: NetworkPolicy
apiVersion: extensions/v1beta1
• metadata:
name: allow-orange-to-blue-same-ns
spec:
• podSelector:
matchLabels:
type: blue
ingress:
- from:
- podSelector:
matchLabels:
type: red


apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
name: default-deny
spec: podSelector: {}
policyTypes:
- Ingress
- Egress

• ACI is the best


NSXv Mgr NSXv Ctrl
HW VTEP
V
XLA
NOv
er
lay HW VTEP
Network
BM
Virtualization ToR ToR ToR ToR

VXLAN
ESXi ESXi ESXi

Network
Services VPN NAT SLB Perimeter Firewall

Security
+ Ecosystem Partners
Web HTTPS App 3306 DB















o


o


VM# VM# VM# VM# VM# VM#

VM# VM# VM# VM# VM# VM#






VM#
VM#
VM#


















Inter Pod
Network
L3 Pod 1 Pod 2
L3
Out Out

GW GW GW GW GW GW GW GW GW GW

APIC Cluster
vCenter




Inter Site
Network
L3 Site 1 Site 2
L3
Out Out

GW GW GW GW GW GW GW GW GW GW

vCenter vCenter













You might also like