Dcac9k Lab Guide 20160501
Dcac9k Lab Guide 20160501
Dcac9k Lab Guide 20160501
Configuring Cisco
Nexus 9000 Series
Switches in ACI Mode
Version 1.2 Revision A
Lab Guide
DCAC9K
Lab Guide
Overview
This guide presents the instructions and other information concerning the lab activities for this course.
Outline
This guide includes these activities:
Lab 10: Configure the APIC Using the REST API (Postman)
Lab 11: Configure the APIC Using the ACI Cobra SDK (Python)
Lab 12: Configure the APIC Using the Cisco APIC REST to Python Adapter (ARYA)
Once you have successfully logged in to a Student Server you will be able to use the applications
installed on the Student Server to access the lab devices for your class.
Student Server names and account credentials will be given to you by your instructor.
Two students may log in to the same Student Server using different accounts; in this case each
student will have a unique Desktop which is not shared with the other student.
The Student Servers are often referred to by a one-digit number (the Student Server Number) which is part of
the DNS and IP address of the Student Server.
One (1) Cisco Nexus C9336PQ Switch running in ACI mode (Spine switch)
Two (2) Cisco Nexus C9396PX Switches running in ACI mode (Leaf switches)
You will have access to all of these devices; however you will be assigned a single Pod within the UCS Lab
Rack:
A Pod is a portion of the ACI Lab Rack that is configured by one or two students.
A Pod Number is used to uniquely identify each Pod. The Pod Number (##) is a value between 11
and 26.
You will be assigned to a Pod for a given lab exercise, possibly with another student depending on
the class size.
During the lab exercises you will be asked to configure the devices in your Pod. Do not configure
any devices outside your assigned Pod unless specifically instructed to do so.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 3
Letter Variables
The Lab Guide for your class uses letter variables (similar to algebra) to represent digits within a command
or command output. Usually, whenever you see one of the capital letters in the following table you should
replace that letter with the correct value; the Lab Guide should also point out when a letter variable is being
used. The variables will be displayed with a font color of red.
For example, if you are currently assigned to Pod 23, and if you are instructed to configure an IP address of
192.168.1.##, the IP address that you should use would be 192.168.1.23. The following table lists all of the
letter variables that are commonly used in the Lab Guide.
Letter Variable
Possible Values
Description
1, 2, or 3
##
11 through 26
A, B, C, or D
@@
You should determine the value of each of these variables before you start each lab exercise. If you do not
use the correct values you may not be able to complete the lab exercise and you may also cause another
students lab devices to malfunction.
This is the only application that can be used to log in to your Student Server.
The shortcut to RDC is typically found on Windows-based systems by clicking Start All
Programs Accessories Remote Desktop Connection. Another way to find RDC is to use the
Search programs and files function in the Windows Start menu.
or
Students using Apple-based computers can download the Microsoft Remote Desktop app from
https://itunes.apple.com/us/app/id715768417?mt=12 .
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 4
User Name
Password
Step 2
Step 3
Verify that your computer is able to access the Internet. A simple test to verify this would be to
use a browser to access www.nterone.com .
Step 4
Verify that your computer has a Remote Desktop Connection (RDC) client installed. Use the
information on the previous page if you are having difficulty finding RDC on your computer.
Step 5
Start the Remote Desktop Connection application. The following window should appear.
Note
The following steps use the Microsoft version of RDC; if you are using an Apple- or Linux-based
computer the screens that you will see will be different.
Step 6
In the Computer field enter the DNS name or IP address of the Student Server that has been
assigned to you.
Step 7
Click the Connect button. The Windows Security window should appear.
Note
If this step fails after several seconds, please contact your class instructor for assistance.
Note
If you are able to access the Internet but are unable to access any of the NterOne Student
Servers you will need to determine if there is a firewall somewhere preventing your computer
from accessing the NterOne Student Servers. This is a common problem for students who are
using a computer at their place of employment, in which case you may need to contact your
companys IT department for assistance.
Step 8
Step 9
Enter the User name and Password needed to connect to the Student Server.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 5
Step 10
Click the OK button. A window should appear which will look similar to the window below
Step 11
Click the check box next to Dont ask me again for connections to this computer and then
click Yes.
Step 12
After a few seconds the login process should finish and the desktop of your Student Server
should appear which will look similar to the window below.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 6
Step 13
The most commonly used applications such as Chrome will have shortcut to them on the
Desktop. Other applications may also be found using the Start menu.
Step 14
From the desktop of your Student Server start the Chrome application.
Step 16
Navigate to the following URL: https://192.168.R0.1 (replace R with your ACI Rack
Number).
Step 17
Note
Please never worry if you see any message like this about your connection not being private in
these labs. Of course, click Proceed and agree with all browser security requests.
Step 18
Click the link labeled Advanced. Chrome will warn you that the security certificate provided by
the APIC is not trusted.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 7
Step 19
Click the link labeled Proceed to 192.168.R0.1 (unsafe). You should now see the APIC sign in
prompt.
Step 20
Username: admin
Mode: Advanced
Note
Step 21
You may see the warning message depicted below. If you do not see this warning message, skip
ahead to Step 25.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 8
Step 22
Step 23
The Deployment Warning Settings window will appear. Click the check box next at the end
of (Global) Show Deployment Warning on Delete/Modify.
Step 24
Step 25
Once you are logged in, you are presented with the Dashboard. You are logged in with global
administrative rights and your view includes all system components.
Note
The ACI Rack that you are using contains only one APIC, which is why the red warning message
is displayed at the top of the application. This warning message will be present throughout this
class.
Step 26
Note the layout of the GUI interface. The top portion is referred to as the Menu bar.
Step 27
Once a tab is selected from the Menu bar, a Submenu bar will appear below the Menu bar.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 9
Step 28
The Navigation pane displays on the left side of the APIC GUI, below the Submenu bar. This
pane provides centralized navigation to all elements of the submenu category. When you
choose a component in the Navigation pane, the object displays in the Work pane that displays
on the right side of the APIC GUI. This pane displays details about the component selected in
the Navigation pane.
Step 29
The upper right-hand corner of the APC GUI indicates the user account with which you logged
in to the APIC GUI. Click the down arrow next to the account name and select Settings from
the drop-down menu.
Step 30
The Application Settings window will appear. These settings affect how the APIC GUI
responds as you use it. Enter the values in the following table.
Field
Value
Checked
Checked
Checked
Unchecked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 10
Step 31
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 11
Configure DNS
Configure NTP
It is critical and important in every way to refer to the NterOne Resource Guide for this class
provided by your instructor. Study it. Use it. Refer to it. These labs demand you use the
Resource Guide. Again and again.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Mode: Advanced
Step 5
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 12
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Tasks that are designated as Instructor Demo are only performed once per ACI fabric.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 6
Step 7
Step 8
Click the next to Fabric Membership in the Navigation pane to expand the view, and notice
the single switch entry under the Fabric Membership folder. This is the leaf switch that the
APIC is connected to, which is not yet registered.
Note
The APICs and the ACI switches use Link Layer Discovery Protocol (LLDP) to discover
connected devices. Devices that are discovered are not automatically added to the fabric; an
administrator must determine which devices should be added to the fabric and then manually
register them.
Step 9
Choose Fabric Membership by clicking on that entry. The Work pane will show a switch with
a serial number that starts with the letters SAL, and ID of 0. Observe that its role is leaf.
Note
Unregistered switches are assigned the Node ID of 0. By default, switches detected by the fabric
are not added to the fabric automatically, they must be added manually.
Step 10
To register this leaf switch, double-click the row in the Work pane; this will allow you to
modify the values of the row. Enter the values in the following table.
Field
Value
NODE ID
101
NODE NAME
Leaf-1
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 13
Note
The Node ID has to be greater than 100 because the APIC reserves the node IDs 1 through 100
for future APICs that may be added to the fabric.
Step 11
Step 12
The APIC will now begin discovering the fabric along with other APICs. Wait 30 to 60 seconds
for the APIC GUI to see other switches in the fabric. You should see an additional switch
appear in the Fabric Membership view.
Note
Observe that the Leaf switch now has a private (RFC 1918) IP address assigned. This address
range is configured on the APIC when first installed, and managed by the APIC for infrastructure
communication across the ACI fabric.
Note
The fabric will discover another switch. Notice under the ROLE that these are spine switches
with their Node ID set to 0.
Step 13
Register the Cisco Nexus 9336PQ spine switch. Enter the values in the following table.
Field
Value
NODE ID
102
NODE NAME
Spine-1
Step 14
With the spine switch now registered, please wait an additional 30 to 60 seconds for the fabric
to discover the second leaf switch.
Step 15
Register the Cisco Nexus 9396PX leaf switch. Enter the values in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 14
Field
Value
NODE ID
103
NODE NAME
Leaf-2
Step 16
In the Navigation pane, click the Topology folder. You should see the complete ACI fabric,
which includes one spine switch, two leaf switches, and one APIC.
Step 17
From your Student Server desktop, start a PuTTY session with APIC-1. There should be a
shortcut on the desktop for APIC-1.
Step 18
Step 19
Execute the show switch command. This command will display a summary of the fabric
switches that are registered with the APIC. The output should show three fabric switches and
contain information similar to what was seen earlier in the GUI.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 15
Step 20
Execute the acidiag fnvread command. This command will display similar information about
the fabric switches.
The acidiag command is useful troubleshooting command that allows you to gather information
about the entire ACI fabric from the APIC command line.
Step 21
Execute the show controller command. This command will display a summary of the APICs
that are connected to this fabric.
Note
The IP addresses assigned in your environment may not match the output. It is a pseudorandom assignment.
Step 22
Execute the show controller detail command. This command will display additional details
about the APIC.
detail
1*
apic1
70987b86-02f6-11e6-b6f8-1516d7032dca
172.19.0.1
0.0.0.0
fc00::1
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 16
STOP!
:
:
:
:
:
:
:
:
:
:
:
192.168.R0.1
fe80::fe5b:39ff:fe2d:4f5a
FCH1835V0RY
1.2(2h)
in-service
available
yes
2014-10-31T05:51:47.000+00:00
2024-10-31T06:01:47.000+00:00
01:01:39:51.000
fully-fit
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 23
Step 24
Step 25
Step 26
In the Navigation pane, expand Tenant mgmt > Security Policies > Out-Of-Band Contracts.
Step 27
Right-click the Out-Of-Band Contracts folder and then select Create Out-Of-Band Contract
from the context menu.
Step 28
The Create Out-Of-Band Contract wizard will appear. Enter the values in the following table;
do NOT change any of the values that are not listed in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 17
Field
Value
Name
OOB-CONTRACT
Scope
VRF
Step 29
In the Subjects subsection, click the plus sign to create a new entry.
Step 30
The Create Contract Subject wizard will appear. In the Name field, type SUBJECT-ANY.
Step 31
In the Filters subsection, click the plus sign to create a new entry.
Step 32
Step 33
Step 34
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 18
Step 35
Click the SUBMIT button to complete the Create Out-Of-Band Contract wizard.
Step 36
In the Navigation pane, expand Tenant mgmt > Node Management EPGs.
Step 37
Right-click the Node Management EPGs folder and then select Create Out-of-Band
Management EPG from the context menu.
Step 38
The Create Out-of-Band Management EPG wizard will appear. In the Name field, type
OOB-MGMT-EPG.
Step 39
In the Provided Out-of-Band Contracts subsection, click the plus sign to create a new entry.
Step 40
Step 41
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 19
Step 42
Click the SUBMIT button to complete the Create Out-of-Band Management EPG wizard.
Step 43
In the Navigation pane, expand Tenant mgmt > Node Management Addresses > Static Node
Management Addresses.
Step 44
Right-click the Static Node Management Addresses folder and then select Create Static
Node Management Addresses from the context menu.
Step 45
The Create Static Node Management Addresses wizard will appear. Enter the values in the
following table.
Field
Value
101
103
Checked
OOB-MGMT-EPG
Step 46
Click the SUBMIT button to complete the Create Static Node Management Addresses
wizard. A warning message will appear indicating that the management IP addresses of the
selected range of nodes will be changed.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 20
Step 47
Step 48
You should now see the IP addresses that have been assigned to the Nexus switches in the
Work pane.
Step 49
In the Navigation pane, expand Tenant mgmt > External Management Network Instance
Profiles.
Step 50
Right-click the External Management Network Instance Profiles folder and then select
Create External Management Network Instance Profile from the context menu.
Step 51
The Create External Management Network Instance Profile wizard will appear. In the
Name field, type EMNIP.
Step 52
In the Consumed Out-of-Band Contracts subsection, click the plus sign to create a new entry.
Step 53
Step 54
Step 55
In the Subnets subsection, click the plus sign to create a new entry.
Step 56
Step 57
Step 58
In the Subnets subsection, click the plus sign to create a new entry.
Step 59
In the IP field, enter 192.168.R0.0/24 (replace R with your ACI Rack Number).
Step 60
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 21
Step 61
Click the SUBMIT button to complete the Create External Management Network Instance
Profile wizard.
Step 62
At this point you have allowed access to the management ports of the Nexus switches from two
different subnets. Next, you will verify that you can connect directly to the Nexus switches.
Step 63
From your Student Server desktop, start a PuTTY session with the Leaf-1 switch. There should
be a shortcut on the desktop for Leaf-1.
Step 64
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Page 22
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 65
Step 66
Step 67
Step 68
In the Navigation pane, expand Global Policies > DNS Profiles > default.
Step 69
In the DNS Providers subsection, click the plus sign to create a new entry.
Step 70
In the ADDRESS field, type 192.168.R0.40 (replace R with your ACI Rack Number).
Step 71
Step 72
Step 73
In the DNS Domains pane click the plus sign to create a new entry.
Step 74
Step 75
Step 76
Step 77
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 23
Step 78
Step 79
Step 80
To verify that DNS name resolution is functioning properly enter the ping leaf-1.dc.local
command. After a few seconds press <Ctrl>+<C> to stop the ping.
Step 81
Enter the ping leaf-1 command; make sure not to include the domain name. After a few
seconds press <Ctrl>+<C> to stop the ping.
time=0.156
time=0.125
time=0.158
time=0.250
time=0.112
ms
ms
ms
ms
ms
--- Leaf-1 ping statistics --5 packets transmitted, 5 received, 0% packet loss, time 4060ms
rtt min/avg/max/mdev = 0.112/0.160/0.250/0.048 ms
Note
The APIC used the IP address of 192.168.R0.101 for leaf-1.dc.local, and it used 172.19.64.95
for leaf-1. The IP address 192.168.R0.101 is the out-of-band address, while 172.19.64.95 is the
infrastructure address assigned to leaf-1 when it was connected to the fabric.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 24
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 82
Step 83
Right-click the DNS Profiles folder and then select Create DNS Profile from the context
menu.
Step 84
The Create DNS Profile wizard will appear. Enter the values in the following table.
Field
Value
Name
DNS-PROFILE
Management EPG
OOB-MGMT-EPG (Out-of-Band)
Step 85
In the DNS Domains pane click the plus sign to create a new entry.
Step 86
Step 87
Step 88
Step 89
In the DNS Providers subsection, click the plus sign to create a new entry.
Step 90
In the ADDRESS field, type 192.168.R0.40 (replace R with your ACI Rack Number).
Step 91
Step 92
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 25
Step 93
Click the SUBMIT button to complete the Create DNS Profile wizard.
Step 94
Step 95
Step 96
In the Navigation pane, expand Tenant mgmt > Networking > VRFs > oob.
Step 97
Near the bottom of the Work pane, in the DNS Labels field, type DNS-PROFILE.
Step 98
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 99
Step 100
Step 101
To verify that DNS name resolution is functioning properly enter the ping leaf-2.dc.local
command. After a few seconds press <Ctrl>+<C> to stop the ping.
STOP!
ms
ms
ms
ms
ms
This Task will be performed by the Instructor; students do NOT perform this Task.
Page 26
Activity Procedure
Complete these steps:
Note
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 102
Step 103
Step 104
Step 105
Step 106
Right-click the RADIUS Providers folder and then select Create RADIUS Provider from the
context menu.
Step 107
The Create RADIUS Provider wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
1234QWer
Step 108
Click the SUBMIT button to complete the Create RADIUS Provider wizard.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 27
In this task, the instructor will configure a local user account to be used as a second account that has full
administrative privileges to the fabric.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 109
Step 110
Step 111
Step 112
Right-click the Local Users folder and then select Create Local User from the context menu.
Step 113
The Create Local User wizard will appear. In STEP 1 > Security, in the Security Domain
subsection, click the checkbox next to all.
Step 114
Click the NEXT button. In STEP 2 > Roles, select Read Write for each of the roles listed.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 28
Step 115
Click the NEXT button. In STEP 3 > User Identity, enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Login ID
admin2
1234QWer
Step 116
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Task 7: Configure the Date and Time Format and NTP (Instructor
Demo)
In this task, the instructor will configure the date and time format of the clock and the NTP server used by the
fabric.
Activity Procedure
Complete these steps:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 29
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 117
Step 118
Step 119
Navigate to Pod Policies > Policies > Date and Time > default.
Step 120
In the Work pane, in the Time Zone drop-down list, select America/New_York.
Step 121
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 122
Step 123
In the Navigation pane, right-click the Date and Time folder and then select Create Date and
Time Policy from the context menu.
Step 124
The Create Date and Time Policy wizard will appear. In STEP 1 > Identity, in the Name file,
type DATE-TIME-POLICY.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 30
Step 125
Step 126
In STEP 2 > NTP Servers, click the plus sign to create a new entry and enter the values in the
following table.
Field
Value
Name
Preferred
Checked
Management EPG
OOB-MGMT-EPG (Out-of-Band)
Step 127
Step 128
Click the FINISH button to complete the Create Date and Time Policy wizard.
Step 129
In the Navigation pane, expand the Pod Policies > Policies > Policy Groups folder.
Step 130
Right-click the Policy Groups folder and then select Create Pod Policy Group from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 31
Step 131
The Create Pod Policy Group wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
POD-POLICY-GROUP
DATE-TIME-POLICY
Step 132
Click the SUBMIT button to complete the Create Pod Policy Group wizard.
Step 133
Step 134
In the Work pane, in the Fabric Policy Group drop-down list, select POD-POLICY-GROUP.
Step 135
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 136
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 32
Step 137
The necessary date and time settings for the fabric are now configured. You can view the date
and time for the fabric at the bottom of the APIC GUI. It may take several seconds for the
correct time to be displayed.
Step 138
Step 139
To verify that NTP is functioning properly on the switch enter the show ntp peer-status
command. You should see that there is a single peer, and the peer is selected for
synchronization.
It may take a few minutes for the switch to synchronize with the peer.
Step 140
Use the show clock command to verify that the clock on the switch is set correctly.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Task 8: Enable HTTP Access for the XML API (Instructor Demo)
In this task, you will enable HTTP access to the APICs so that the XML API is accessible via HTTP.
Activity Procedure
Complete these steps:
Note
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 141
Step 142
Step 143
Navigate to Pod Policies > Policies > Management Access > default.
Step 144
In the HTTP section, in the Admin State drop-down list, select Enabled.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 33
Step 145
Click the SUBMIT button to commit the configuration changes. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 146
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Private Networks are only instantiated on a leaf when an EPG for that Private Network has
endpoints connected off the leaf.
MP-BGP is not enabled by default in ACI fabric. You will configure a BGP policy, specifying the BGP AS
number and specific spine nodes as BGP route reflectors. Once configured the APIC will automatically
configure iBGP peering between leaf and spine and specify leaf switches as route reflector clients. APIC also
automatically generates the required configuration for route redistribution on the border leaf.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 147
Step 148
Step 149
In the Navigation pane, select Pod Policies > Policies > BGP Route Reflector default.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 34
Step 150
Note
The iBGP ASN must match the external router configuration if iBGP will be configured between
the ACI Fabric and an external network. If using static routes, OSPF, or EIGRP between the ACI
Fabric and an external network, the iBGP ASN value can be any valid value.
Step 151
In the Route Reflector Nodes subsection, click the plus sign to start the Create Route
Reflector Node Policy EP wizard.
Step 152
Step 153
Click the SUBMIT button to complete the wizard. Node ID 102 will now be listed in the Route
Reflector Nodes subsection.
Step 154
Click the SUBMIT button in the Work pane. A Policy Usage Warning will appear indicating
the other objects that will be affected by the changes.
Step 155
Note
This configuration applies to the entire fabric, and is not enforced per Tenant. BGP will be
automatically enabled on any leaf switch which has an external Layer 3 network attached, as
well as any leaf switch where the Private Network associated with the Layer 3 external network
are instantiated (leafs which do not have the Private Network associated preserve the hardware
resources by not running BGP or not storing the routes).
Note
Once the border leaf forms a neighbor relationship, it will propagate Tenant routes to the
external router. Users have control of which Tenant subnets to advertise to external routers.
When specifying subnets under the bridge domain for a given Tenant, the user has the choice to
specify the scope (private, public, or shared) of a subnet.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 35
Note
For security and separation, MP-BGP maintains separate BGP routing tables for each ACI
Private Network.
Step 156
To verify that the BGP route reflectors are functioning, navigate to Fabric > Inventory > Pod
1 > Spine-1 > Protocols > BGP > BGP for VRF overlay-1 > Sessions. You should see that
there are two established BGP sessions, one to each leaf switch.
Step 157
From your Student Server desktop, start a PuTTY session with Spine-1. There should be a
shortcut on the desktop for Spine-1.
Step 158
Step 159
Verify that the BGP sessions to the leaf switches are established by entering the show bgp
sessions vrf overlay-1 command.
ASN
Flaps LastUpDn|LastRead|LastWrit St Port(L/R) Notif(S/R)
100 0
00:02:31|never
|never
E 179/48420 0/0
100 0
00:02:30|never
|never
E 179/52730 0/0
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 36
Create a Tenant
Create a VRF
Create Subnets
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Note
By default there are three pre-existing tenants: common, infra, and mgmt.
The common tenant contains system generated pre-configured policies that govern the
operation of resources accessible to all tenants, such as firewalls, load balancers, Layer 4 to
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 37
Layer 7 services, intrusion detection appliances, and so on. Common tenant polices are
configurable by the fabric administrator.
The infra (infrastructure) tenant contains policies that govern the operation of infrastructure
resources such as the fabric VXLAN overlay. It also enables a fabric provider to selectively
deploy resources to one or more user tenants.
The management tenant contains policies that govern the operation of fabric management
functions used for in-band and out-of-band configuration of fabric nodes. The management
tenant contains an out-of-bound address space for the APIC/fabric internal communications that
is outside the fabric data path that provides access through the management port of the
switches. The management tenant enables discovery and automation of communications with
virtual machine controllers.
Step 7
Step 8
The Create Tenant wizard will appear. Enter the values in the following table; do NOT change
any of the values that are not listed in the following table.
Field
Value
Name
Description
Note
Throughout all labs, ## refers to your pod, as assigned by your instructor. Pay very close
attention in all labs to be sure you in YOUR pod.
For all NterOne ACI labs, your Tenant = your Pod.
Step 9
Step 10
The APIC GUI will take you to the Quick Start folder of the Tenant that you just created.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 38
Activity Procedure
Complete these steps:
Step 11
In the Navigation pane, expand Tenant POD## > Networking > VRFs.
Step 12
Right-click the VRFs folder and then select Create VRF from the context menu.
Step 13
The Create VRF wizard will appear. In STEP 1 > VRF, enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Unchecked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 39
Step 14
Note
What does Policy Enforcement mean? By default policy enforcement is enforced on a context,
and is performed by either the ingress or egress Leaf. As traffic enters the leaf switch the packet
fabric header is marked with the EPG of the source endpoint. The leaf switch then performs a
forwarding lookup on the packet destination IP address within the tenant space. A unicast (/32)
or subnet prefix (not /32) hit provides the EPG of the destination endpoint destination subnet
prefix, and either the local interface or the remote leaf switch VTEP IP address where the
destination endpoint subnet prefix is present.
Note
A miss causes the packet to be sent to the forwarding proxy in the spine switch, which performs
a forwarding table lookup. If this is a miss, the packet is dropped. If it is a hit, the packet is sent
to the egress leaf switch that contains the destination endpoint. Because the egress leaf switch
knows the EPG of the source and destination, it performs the security policy enforcement.
Note
On the egress leaf switch, the source IP address and source EPG information will be stored in
the local forwarding table through learning. Because most flows are bidirectional, a return packet
populates the forwarding table on both sides of the flow, which enables the traffic to be ingress
filtered in both directions
Activity Procedure
Complete these steps:
Step 15
In the Navigation pane, expand Tenant POD## > Networking > Bridge Domains.
Step 16
Right-click the Bridge Domains folder and then select Create Bridge Domain from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 40
Step 17
The Create Bridge Domain wizard will appear. In STEP 1 > Main, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
VRF
Step 18
Click the NEXT button. In STEP 2 > L3 Configurations, do not make any changes.
Step 19
Click the NEXT button. In STEP 3 > Advanced/Troubleshooting, do not make any changes.
Step 20
Click the FINISH button to complete the Create Bridge Domain wizard.
Activity Procedure
Complete these steps:
Step 21
In the Navigation pane, expand Tenant POD## > Networking > Bridge Domains > POD##BD > Subnets.
Step 22
Right-click the Subnets folder and then select Create Subnet from the context menu.
Step 23
The Create Subnet wizard will appear. Enter the values in the following table; do NOT change
any of the values that are not listed in the following table.
Field
Value
Name
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 41
Note
Field
Value
Scope
Private to VRF
The Scope of a subnet defines the network visibility of the subnet. The scope can be:
Private to VRF Defines subnets under a BD to only be used in that Tenant (will not be leaked).
Advertised Externally Defines subnets under an endpoint group to route leak to other Tenants in the
Fabric.
Shared between VRFs Defines subnets under an endpoint group to route leak for shared services
(endpoint groups in a different VRF).
Step 24
Click the SUBMIT button. The subnet you just created will be visible in the Subnets
subsection.
Step 25
Repeat the previous three steps to create a subnet with the Gateway IP of 10.##.2.254/24
(replace ## with your assigned 2-digit Pod Number)
Step 26
Repeat the previous three steps to create a subnet with the Gateway IP of 10.##.3.254/24
(replace ## with your assigned 2-digit Pod Number)
Step 27
In the Navigation pane, in the Subnets folder, be sure you see the three Subnets listed. Make
sure the second octet of the IP address is your Pod ##, which is the same number as your
Tenant. The screen shot here is an example for pod 11.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 42
Create Filters
Create Contracts
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Step 7
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 8
In the Navigation pane, expand Tenant POD## > Security Policies > Filters.
Step 9
Right-click the Filters folder and then select Create Filter from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 43
Step 10
The Create Filter wizard will appear. In the Name field type POD##-FILTER-ANY (replace
## with your assigned 2-digit Pod Number).
Step 11
In the Entries subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
ANY
EtherType
Unspecified
Step 12
Step 13
Click the SUBMIT button to complete the Create Filter wizard. You should now see the filters
you just created in the Filters folder.
Step 14
Right-click the Filters folder and then select Create Filter from the context menu.
Step 15
The Create Filter wizard will appear. In the Name field type POD##-FILTER-PORT-80
(replace ## with your assigned 2-digit Pod Number).
Step 16
In the Entries subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
PORT-80
EtherType
IP
IP Protocol
tcp
Unchecked
Stateful
Checked
1024
65535
80
80
Unspecified
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 44
Step 17
Step 18
Click the SUBMIT button to complete the Create Filter wizard. You should now see the filters
you just created in the Filters folder.
Step 19
Right-click the Filters folder and then select Create Filter from the context menu.
Step 20
The Create Filter wizard will appear. In the Name field type POD##-FILTER-PORT-81
(replace ## with your assigned 2-digit Pod Number).
Step 21
In the Entries subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
PORT-81
EtherType
IP
IP Protocol
tcp
Unchecked
Stateful
Checked
1024
65535
81
81
Unspecified
Step 22
Step 23
Click the SUBMIT button to complete the Create Filter wizard. You should now see the filters
you just created in the Filters folder.
Step 24
Right-click the Filters folder and then select Create Filter from the context menu.
Step 25
The Create Filter wizard will appear. In the Name field type POD##-FILTER-PORT-82
(replace ## with your assigned 2-digit Pod Number).
Step 26
In the Entries subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
PORT-82
EtherType
IP
IP Protocol
tcp
Unchecked
Stateful
Checked
1024
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 45
Field
Value
65535
82
82
Unspecified
Step 27
Step 28
Click the SUBMIT button to complete the Create Filter wizard. You should now see the filters
you just created in the Filters folder.
Step 29
Right-click the Filters folder and then select Create Filter from the context menu.
Step 30
The Create Filter wizard will appear. In the Name field type POD##-FILTER-ICMP (replace
## with your assigned 2-digit Pod Number).
Step 31
In the Entries subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
ICMP
EtherType
IP
IP Protocol
icmp
Unchecked
Step 32
Step 33
Click the SUBMIT button to complete the Create Filter wizard. You should now see the filters
you just created in the Filters folder. At this point there should be five filters listed in the
Contracts folder.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 46
Activity Procedure
Complete these steps:
Step 34
In the Navigation pane, expand Tenant POD## > Security Policies > Contracts.
Step 35
Right-click the Contracts folder and then select Create Contract from the context menu.
Step 36
The Create Contract wizard will appear. In the Name field type POD##-CONTRACT-ANY
(replace ## with your assigned 2-digit Pod Number).
Step 37
In the Subjects subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 47
Field
Value
Name
SUBJECT-ANY
Checked
Checked
Step 38
In the Filter Chain subsection, click the plus sign to create a new entry. In the drop-down list,
select POD##-FILTER-ANY.
Step 39
Step 40
Click the SUBMIT button to complete the Create Contract wizard. You should now see the
contract you just created in the Contracts folder.
Step 41
Right-click the Contracts folder and then select Create Contract from the context menu.
Step 42
The Create Contract wizard will appear. In the Name field type POD##-CONTRACT-DBAPP (replace ## with your assigned 2-digit Pod Number).
Step 43
In the Subjects subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
SUBJECT-ANY
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 48
Field
Value
Checked
Checked
Step 44
In the Filter Chain subsection, click the plus sign to create a new entry. In the drop-down list,
select POD##-FILTER-ANY.
Step 45
Step 46
Click the SUBMIT button to complete the Create Contract wizard. You should now see the
contract you just created in the Contracts folder.
Step 47
Right-click the Contracts folder and then select Create Contract from the context menu.
Step 48
The Create Contract wizard will appear. In the Name field type POD##-CONTRACT-APPWEB (replace ## with your assigned 2-digit Pod Number).
Step 49
In the Subjects subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
SUBJECT-ANY
Checked
Checked
Step 50
In the Filter Chain subsection, click the plus sign to create a new entry. In the drop-down list,
select POD##-FILTER-ANY.
Step 51
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 49
Step 52
Click the SUBMIT button to complete the Create Contract wizard. At this point there should
be three contracts listed in the Contracts folder.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 50
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Step 7
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 8
Step 9
Right-click the Application Profiles folder and then select Create Application Profile from
the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 51
Step 10
The Create Application Profile wizard will appear. In the Name field type POD##APPLICATION-PROFILE (replace ## with your assigned 2-digit Pod Number).
Step 11
In the EPGs subsection, click the plus sign to create a new EPG. Enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
BD
Provided Contract
Step 12
Step 13
In the EPGs subsection, click the plus to create a new EPG. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 52
Field
Value
BD
Provided Contract
Consumed Contract
Step 14
Step 15
In the EPGs subsection, click the plus to create a new EPG. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
BD
Consumed Contract
Step 16
Click the OK button. You should now see three EPGs listed in the EPGs pane.
Step 17
Click the SUBMIT button to complete the Create Application Profile wizard.
Step 18
In the Navigation pane, expand the Application Profiles folder, and then click the POD##APPLICATION-PROFILE object. In the Work pane, the first tab that is presented is the
Topology tab. This tab displays a diagram that logically represents the application profile.
Note
You may need to drag-and-drop the various icons in order to create a diagram that is easier to
view.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 53
Step 19
In the Navigation pane, expand Tenant POD## > Security Policies > Contracts > POD##CONTRACT-APP-WEB. In the Work pane, the first tab that is presented is the Topology tab.
This tab displays a diagram that logically represents the contract and its relationship with the
end point groups.
Note
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 54
Register APIC to VMware vCenter Server, creating a Distributed Virtual Switch inside VMware's
Network construct
Verify that the ACI DVS has been created and the connection between APIC and vCenter Server is
established
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 55
Note
A VLAN pool specifies the VLAN IDs or ranges used for VLAN encapsulation that the VMM
domain consumes. Each time you associate an EPG to a VMM domain a VLAN ID is taken from
the VLAN pool and assigned to the virtual machine group that is created within the VMM domain
(e.g. a port group within the ACI DVS within a vCenter).
Activity Procedure
Complete these steps:
Step 8
Step 9
Step 10
Step 11
Step 12
Right-click the VLAN folder and then select Create VLAN Pool from the context menu.
Step 13
The Create VLAN Pool wizard will appear. Enter the values in the following table.
Field
Value
Name
Allocation Mode
Dynamic Allocation
Step 14
In the Encap Blocks subsection, click the plus sign to create a new VLAN range. Enter the
values in the following table.
Field
Value
Range (From)
Range (To)
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 56
Step 15
Step 16
Click the SUBMIT button to complete the Create VLAN Pool wizard. You should now see the
VLAN you just created in the VLAN folder.
Activity Procedure
Complete these steps:
Step 17
Step 18
In the Navigation pane, right-click the VMware folder, and then select Create vCenter
Domain from the context menu.
Step 19
The Create vCenter Domain wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 57
Field
Value
Name
Virtual Switch
VLAN Pool
Step 20
In the vCenter Credentials subsection, click the plus sign to create a new vCenter credential.
Enter the values in the following table.
Field
Value
Name
VCENTER-CREDENTIAL
Username
root
1234QWer
Step 21
Step 22
In the vCenter/vShield subsection, click the plus sign to create a new vCenter connection.
Enter the values in the following table; do NOT change any of the values that are not listed in
the following table.
Field
Value
Type
vCenter
Name
VCENTER-CONTROLLER
Host Name
Datacenter
Associated Credential
VCENTER-CREDENTIAL
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 58
Note
The name of the Datacenter must exactly match the name as it appears in the vSphere Client,
otherwise the APIC will not be able to locate and configure the correct Datacenter in the vCenter
Server. In this lab the D at the beginning of the name and the vCenter letter are capitalized; the
rest of the name is in lower case.
Step 23
Step 24
Click the SUBMIT button to complete the Create vCenter Domain wizard. You should now
see the VMM domain you just created in the VMware folder.
Activity Procedure
Complete these steps:
Note
The following steps demonstrate how you can also verify the connection between the APIC and
the vCenter server by using the vSphere client to view that the ACI DVS has been created.
Step 25
Step 26
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 59
Step 27
Expand the Datacenter and POD##-VMM-DOMAIN folders. You will notice that a new DVS
has been created named POD##-VMM-DOMAIN and there are two default port groups: one
port group for DVS uplinks and another port group named quarantine.
Step 28
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 60
The Instructor of the class should perform this lab exercise using Pod Number 00. The
policies will be used in subsequent lab exercises during instructor demonstrations.
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI).
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
A Link Level Policy for leaf switch interfaces that will be configured for a speed of 1 Gbps
A Link Level Policy for leaf switch interfaces that will be configured for a speed of 10 Gbps
Activity Procedure
Complete these steps:
Step 6
Step 7
Step 8
Step 9
Right-click the Link Level folder and then select Create Link Level Policy from the context
menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 61
Step 10
The Create Link Level Policy wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
Auto Negotiation
Off
Speed
1 Gbps
Step 11
Click the SUBMIT button to complete the Create Link Level Policy wizard.
Step 12
Right-click the Link Level folder and then select Create Link Level Policy from the context
menu.
Step 13
The Create Link Level Policy wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
Auto Negotiation
Off
Speed
10 Gbps
Step 14
Click the SUBMIT button to complete the Create Link Level Policy wizard.
Page 62
A CDP Interface Policy for leaf switch interfaces that will be configured to enable CDP
A CDP Interface Policy for leaf switch interfaces that will be configured to disable CDP
Activity Procedure
Complete these steps:
Step 15
Step 16
Right-click the CDP Interface folder and then select Create CDP Interface Policy from the
context menu.
Step 17
The Create CDP Interface Policy wizard will appear. Enter the values in the following table.
Field
Value
Name
Admin State
Enabled
Step 18
Click the SUBMIT button to complete the Create CDP Interface Policy wizard.
Step 19
Right-click the CDP Interface folder and then select Create CDP Interface Policy from the
context menu.
Step 20
The Create CDP Interface Policy wizard will appear. Enter the values in the following table.
Field
Value
Name
Admin State
Disabled
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 63
Step 21
Click the SUBMIT button to complete the Create CDP Interface Policy wizard.
An LLDP Interface Policy for leaf switch interfaces that will be configured to enable LLDP
An LLDP Interface Policy for leaf switch interfaces that will be configured to disable LLDP
Activity Procedure
Complete these steps:
Step 22
Step 23
Right-click the LLDP Interface folder and then select Create LLDP Interface Policy from
the context menu.
Step 24
The Create LLDP Interface Policy wizard will appear. Enter the values in the following table.
Field
Value
Name
Receive
State
Enabled
Transmit
State
Enabled
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 64
Step 25
Click the SUBMIT button to complete the Create LLDP Interface Policy wizard.
Step 26
Right-click the LLDP Interface folder and then select Create LLDP Interface Policy from
the context menu.
Step 27
The Create LLDP Interface Policy wizard will appear. Enter the values in the following table.
Field
Value
Name
Receive
State
Disabled
Transmit
State
Disabled
Step 28
Click the SUBMIT button to complete the Create LLDP Interface Policy wizard.
A PortChannel Policy for leaf switch interfaces that will be added to a port channel that uses LACP
in active mode
A PortChannel Policy for leaf switch interfaces that will be added to a port channel that does not use
LACP (static mode)
Activity Procedure
Complete these steps:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 65
Step 29
Step 30
Right-click the PortChannel Policies folder and then select Create PortChannel Policy from
the context menu.
Step 31
The Create PortChannel Policy wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
Mode
LACP Active
Step 32
Click the SUBMIT button to complete the Create PortChannel Policy wizard.
Step 33
Right-click the PortChannel Policies folder and then select Create PortChannel Policy from
the context menu.
Step 34
The Create PortChannel Policy wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
Mode
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 66
Step 35
Click the SUBMIT button to complete the Create PortChannel Policy wizard.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 67
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
An attachable entity profile (AEP) represents a group of external entities with similar
infrastructure policy requirements. The infrastructure policies consist of physical interface
policies, for example, Cisco Discovery Protocol (CDP), Link Layer Discovery Protocol (LLDP),
maximum transmission unit (MTU), and Link Aggregation Control Protocol (LACP). A VM
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 68
Management (VMM) domain automatically derives the physical interfaces policies from the
interface policy groups that are associated with an AEP.
Activity Procedure
Complete these steps:
Note
WARNING: Only one student per vCenter server may perform the steps in this Task.
Note
WARNING: Identify which student will complete this Task. If you are not the student
selected to complete this Task, do not make any configuration changes in the APIC GUI.
Step 8
Step 9
Step 10
Step 11
Right-click the Attachable Access Entity Profiles folder and then select Create Attachable
Access Entity Profile from the context menu.
Step 12
The Create Attachable Access Entity Profile wizard will appear. In STEP 1 > Profile, enter
the values in the following table.
Field
Value
Name
Checked
Step 13
Click the NEXT button. In STEP 2 > Association to Interfaces enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
vSwitch
Policies
Specify
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 69
Field
Value
CDP Policy
LLDP Policy
Step 14
Click the FINISH button to complete the Create Attachable Access Entity Profile wizard.
Activity Procedure
Complete these steps:
Note
Step 15
Navigate to Global Policies > Attachable Access Entity Profiles > VCENTER-@-AEP.
Step 16
In the Work pane, in the Domains (VMM, Physical or External) Associated to Interfaces
subsection, click the plus sign to associate your VMM domain.
Step 17
A Policy Usage Warning will appear indicating the other objects that will be affected by the
changes. Click the CONTINUE button.
Step 18
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 70
Step 19
Activity Procedure
Complete these steps:
Note
WARNING: Only one student per ESXi Host may perform the steps in this Task.
Note
WARNING: Identify which student will complete this Task. If you are not the student
selected to complete this Task, do not make any configuration changes in the APIC GUI.
Step 20
Step 21
Right-click the Policy Groups folder and then select Create Access Port Policy Group from
the context menu.
Step 22
The Create Access Port Policy Group wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 71
Field
Value
CDP Policy
LLDP Policy
Step 23
Click the SUBMIT button to complete the Create Access Port Policy Group wizard.
Activity Procedure
Complete these steps:
Note
WARNING: Only one student per ESXi Host may perform the steps in this Task.
Note
WARNING: Identify which student will complete this Task. If you are not the student
selected to complete this Task, do not make any configuration changes in the APIC GUI.
Step 24
Step 25
Right-click the Profiles folder and then select Create Interface Profile from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 72
Step 26
The Create Interface Profile wizard will appear. In the Name field, type ESXI-@@INTERFACE-PROFILE (replace @@ with your assigned ESXi host ID).
WARNING: Slow down and be VERY careful with the following entries. Follow the table exactly!
Step 27
In the Interface Selectors subsection, click the plus sign to create a new entry. The Create
Access Port Selector wizard will appear. Enter the values in the following table; do NOT
change any of the values that are not listed in the following table.
Field
Value
Name
INTERFACE-SELECTOR
Interface ID
ESXi-A1: 1/33
ESXi-A2: 1/34
ESXi-B1: 1/35
ESXi-B2: 1/36
ESXi-C1: 1/37
ESXi-C2: 1/38
ESXi-D1: 1/39
ESXi-D2: 1/40
Interface Policy
Group
Step 28
Click the OK button to complete the Create Access Port Selector wizard.
Step 29
Click the SUBMIT button to complete the Create Interface Profile wizard.
Page 73
In this task, you will create a Switch Profile that will be used in a subsequent Task.
Activity Procedure
Complete these steps:
Note
Only one student per ESXi Host may perform the steps in this Task.
Note
Identify which student will complete this Task. If you are not the student selected to
complete this Task, do not make any configuration changes in the APIC GUI.
Step 30
Step 31
Right-click the Profiles folder and then select Create Switch Profile from the context menu.
Step 32
The Create Switch Profile wizard will appear. In STEP 1 > PROFILE, in the Name field,
type ESXI-@@-SWITCH-PROFILE (replace @@ with your assigned ESXi host ID).
WARNING: Slow down and be VERY careful with the following entries. Follow the table exactly!
Step 33
Step 34
In the Switch Selectors subsection, click the plus sign to create a new entry. Enter the values in
the following table.
Field
Value
Name
SWITCH-SELECTOR
Blocks
ESXi-A1: 101
ESXi-A2: 103
ESXi-B1: 101
ESXi-B2: 103
ESXi-C1: 101
ESXi-C2: 103
ESXi-D1: 101
ESXi-D2: 103
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 74
Step 35
Click the NEXT> button. In STEP 2 > Associations, in the Interface Selector Profiles pane,
select ESXI-@@-INTERFACE-PROFILE (replace @@ with your assigned ESXi host
ID).
Step 36
Click the FINISH button to complete the Create Switch Profile wizard.
Step 37
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 38
Step 39
From your Student Server desktop, start a PuTTY session with Leaf-2. There should be a
shortcut on the desktop for Leaf-2.
Step 40
WARNING
Slow down and be VERY careful verifying the following entries. Be sure to review the NterOne
Resource Guide right now. Note the drawing that shows only one cable from each ESXi host to
a leaf switch, and that the other ESXi host connects to the other leaf switch.
Step 41
Execute the show interface e1/XX brief command using the interface number corresponding to
your ESXi host. This command will show you the status of the interface connected to your
ESXi host. The interface should be in the up state, however there will not be any traffic between
the leaf switch and the ESXi host until the ESXi host has been configured to use the interface.
Interface ID
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 75
-------------------------------------------------------------------------------Ethernet
VLAN
Type Mode
Status Reason
Speed
Port
Interface
Ch #
-------------------------------------------------------------------------------Eth1/XX
0
eth trunk
up
none
10G(D)
--
Activity Procedure
Complete these steps:
Note
Step 42
Step 43
Step 44
Step 45
Right-click the POD##-VMM-DOMAIN distributed switch and select Add Host from the
context menu.
Step 46
The Add Host to vSphere Distributed Switch wizard will appear. The first step of the wizard
is Select Host and Physical Adapters.
WARNING
Slow down and be VERY careful with the following entries. Follow the table exactly!
Step 47
You will be selecting one vmnic interface from both of the hosts listed; these vmnics will be
connected to your VMM domain distributed virtual switch. There will be several physical
adapters listed under each host. Use the following table to determine the vmnic interfaces that
you should select; select the same vmnic interface on both hosts.
Pod Number
Vmnic Interface
Vmnic Interface
11
esxi-a1.dc.local
vmnic5
esxi-a2.dc.local
vmnic5
12
esxi-a1.dc.local
vmnic6
esxi-a2.dc.local
vmnic6
13
esxi-a1.dc.local
vmnic7
esxi-a2.dc.local
vmnic7
14
esxi-a1.dc.local
vmnic8
esxi-a2.dc.local
vmnic8
15
esxi-b1.dc.local
vmnic5
esxi-b2.dc.local
vmnic5
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 76
Pod Number
Vmnic Interface
Vmnic Interface
16
esxi-b1.dc.local
vmnic6
esxi-b2.dc.local
vmnic6
17
esxi-b1.dc.local
vmnic7
esxi-b2.dc.local
vmnic7
18
esxi-b1.dc.local
vmnic8
esxi-b2.dc.local
vmnic8
19
esxi-c1.dc.local
vmnic5
esxi-c2.dc.local
vmnic5
20
esxi-c1.dc.local
vmnic6
esxi-c2.dc.local
vmnic6
21
esxi-c1.dc.local
vmnic7
esxi-c2.dc.local
vmnic7
22
esxi-c1.dc.local
vmnic8
esxi-c2.dc.local
vmnic8
23
esxi-d1.dc.local
vmnic5
esxi-d2.dc.local
vmnic5
24
esxi-d1.dc.local
vmnic6
esxi-d2.dc.local
vmnic6
25
esxi-d1.dc.local
vmnic7
esxi-d2.dc.local
vmnic7
26
esxi-d1.dc.local
vmnic8
esxi-d2.dc.local
vmnic8
Step 48
Step 49
The Network Connectivity step will appear. Click the Next button.
Step 50
The Virtual Machine Networking step will appear. Click the Next button.
Step 51
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 77
Step 52
Step 53
Click the Hosts tab in the Work pane. You should see your ESXi hosts listed there and in a
connected state.
Step 54
Step 55
Execute the show cdp neighbors command. You should see that the leaf switch is receiving
CDP information from the ESXi host. It may take a few minutes for the CDP entries to appear.
Local Intrfce
Eth1/??
Hldtme
143
Capability
S
Platform
VMware ESX
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Port ID
vmnic?
Page 78
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Activity Procedure
Complete these steps:
Step 8
Step 9
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 10
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-APP-EPG.
Step 11
Right-click the EPG POD##-APP-EPG folder and then select Add VMM Domain
Association from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 79
Step 12
The Add VMM Domain Association wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Deploy Immediacy
Immediate
Resolution Immediacy
Immediate
Note
Resolution Immediacy controls when the policies are downloaded to the leaf. Immediate
specifies that EPG policies (including contracts and filters) are downloaded to the leaf upon
hypervisor attachment to VDS. LLDP or OpFlex permissions are used to resolve the hypervisor
to leaf node attachments. On Demand specifies that EPG policies are downloaded to the leaf
only when a pNIC attaches to the hypervisor connector and a VM is placed in the port group
(EPG).
Note
Deploy Immediacy controls when the policy is pushed into the hardware policy CAM. Immediate
specifies that the policy is programmed in the hardware policy CAM as soon as the policy is
downloaded in the leaf software. On Demand specifies that the policy is programmed in the
hardware policy CAM only when the first packet is received through the data path. This process
helps to optimize the hardware space.
Step 13
Click the SUBMIT button to complete the Add VMM Domain Association wizard.
Activity Procedure
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 80
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-DB-EPG.
Step 15
Right-click the EPG POD##-DB-EPG folder and then select Add VMM Domain Association
from the context menu.
Step 16
The Add VMM Domain Association wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Deploy Immediacy
Immediate
Resolution Immediacy
Immediate
Step 17
Click the SUBMIT button to complete the Add VMM Domain Association wizard.
Activity Procedure
Complete these steps:
Step 18
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-WEB-EPG.
Step 19
Right-click the EPG POD##-WEB-EPG folder and then select Add VMM Domain
Association from the context menu.
Step 20
The Add VMM Domain Association wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Deploy Immediacy
Immediate
Resolution Immediacy
Immediate
Step 21
Click the SUBMIT button to complete the Add VMM Domain Association wizard.
Task 4: Verify the Creation of the ACI DVS Port Groups within vCenter
In this task, you will verify that the correct ACI DVS port groups were created within the vCenter.
Activity Procedure
Complete these steps:
Step 22
Step 23
Step 24
Step 25
There needs to be three new port groups listed under the ACI DVS, each of which will
correspond to the EPGs within your application profile. The name of each port group is a
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 81
combination of the Tenant, Application Profile, and EPG names. If the port groups dont show
up, review your prior lab steps for any misconfigurations.
Step 26
Right-click one of the port groups that were created and then select Edit Settings from the
context menu.
Step 27
In the Settings window that appears, in the left-hand side click VLAN. You will see the VLAN
ID that was assigned to the port group by the APIC. The VLAN ID was taken from the VLAN
pool associated with the VMM domain associated with vCenter.
Step 28
Look at the other settings of the port group which were assigned by the APIC.
Step 29
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 30
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 82
Step 31
Execute the show vrf command. You should now see that a VRF has been created in the fabric
corresponding to the VRF used by your application profile (within your pod). The name of the
VRF will be the combination of the names of the Tenant and Private Network (VRF).
Step 32
VRF-ID State
3 Up
2 Up
4 Up
5 Up
6 Up
Reason
------
Execute the show vlan extended command. You should now see that VLANs have been
created corresponding to the EPGs that you have associated to the vCenter server.
Type
----enet
enet
enet
enet
enet
Vlan-mode
---------CE
CE
CE
CE
CE
Encap
------------------------------vxlan-16777209, vlan-4093
vxlan-16646014
vlan-3117
vlan-3114
vlan-3111
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 83
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Activity Procedure
Complete these steps:
Step 8
Return to the VMware vSphere Client application. Be sure you are connected to your vCenter,
and not to any ESXi host directly.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 84
Step 9
Step 10
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter). You should see three virtual machines which are assigned to your Pod (replace ##
with your assigned Pod number):
Virtual Machine
IP Address
Default Gateway
Pod##-App
10.##.1.1 /24
10.##.1.254
Pod##-DB
10.##.2.1 /24
10.##.2.254
Pod##-Web
10.##.3.1 /24
10.##.3.254
Step 11
Right-click the Pod##-App VM and then select Edit Settings from the context menu.
Step 12
Step 13
Step 14
In the right-hand side of the window, click the Network label setting and then select
POD##|POD##-APPLICATION-PROFILE|POD##-APP-EPG from the drop-down list.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 85
Step 15
Click the OK button to save the changes to the properties of the virtual machine
Step 16
Right-click the Pod##-App VM and then select Power > Power On from the context menu.
Step 17
After a few seconds you should see the powered on icon next to the virtual machine. If you see
this, skip ahead to the next Task.
Step 18
In some cases it is possible that when you power on a virtual machine you will see a small i
appear on the virtual machine icon:
Step 19
If this occurs, select the virtual machine, and then select the Summary tab in the Work pane.
You will see a question presented to you regarding the state of the virtual machine.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 86
Step 20
Select I Moved It and then click the OK button. The VM will then complete the power on
process.
Activity Procedure
Complete these steps:
Step 21
Right-click the Pod##-DB VM and then select Edit Settings from the context menu.
Step 22
Step 23
Step 24
In the right-hand side of the window, click the Network label setting and then select
POD##|POD##-APPLICATION-PROFILE|POD##-DB-EPG from the drop-down list.
Step 25
Click the OK button to save the changes to the properties of the virtual machine
Step 26
Right-click the Pod##-DB VM and then select Power > Power On from the context menu.
Activity Procedure
Complete these steps:
Step 27
Right-click the Pod##-Web VM and then select Edit Settings from the context menu.
Step 28
Step 29
Step 30
In the right-hand side of the window, click the Network label setting and then select
POD##|POD##-APPLICATION-PROFILE|POD##-Web-EPG from the drop-down list.
Step 31
Click the OK button to save the changes to the properties of the virtual machine
Step 32
Right-click the Pod##-Web VM and then select Power > Power On from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 87
Activity Procedure
Complete these steps:
Step 33
Right-click the Pod##-App VM and then select Open Console from the context menu.
Step 34
The console window for Pod##-App will appear. You will see the App servers desktop.
Step 35
Step 36
Verify that the App server can ping the DB server using the ping 10.##.2.1 command.
Step 37
Verify that the App server can ping the Web server using the ping 10.##.3.1 command.
Step 38
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 39
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 88
Step 40
Step 41
The output of the show mac address-table command does not give you much information about
the virtual machines and the port groups (EPGs) to which they belong. Execute the show
endpoint detail command to see more information about the virtual machines. In the output
you can see the MAC address of each virtual machine, the name of the port group, and the
VLAN ID assigned to the port group to which it belongs.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 89
Create a complete Tenant and Application Profile configuration using the REST API
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
In the Chrome browser, in the upper left-hand side of the window, click the Apps button.
Step 7
Icons for the Google plug-ins that have been installed in the Chrome browser will appear. Click
the Postman icon.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 90
Step 8
Item Number
The Postman application will start in another window. The following table describes the
important parts of the Postman interface.
Description
History Tab a running list of all REST commands sent during this session
Collections Tab a location where you can save REST commands for future use
URL of REST API call to the target device (e.g. the APIC)
Identifies the type of data being sent (in item 8) in the REST command
Step 9
After you send a command to the REST API of the target device (e.g. the APIC), a response (or
error) is returned from the device and displayed in the lower half of the Postman interface.
Item Number
Description
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 91
Activity Procedure
Complete these steps:
Step 10
In the Postman interface, choose POST from the HTML Methods drop-down menu.
Step 11
Note
It may be simpler to enter this URL by copying and pasting it from this document into Postman.
Step 12
Click the Body tab; this is the location where the data that will be sent to the APIC will be
entered.
Step 13
Click the raw radio button to set the data encoding method.
Step 14
Step 15
Type the following in the text field under the raw button:
<aaaUser name="admin" pwd="1234QWer" />
Note
It may be simpler to enter this text by copying and pasting it from this document into Postman.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 92
Step 16
Step 17
You should see the following results, indicating a successful login to the APIC.
Note
You can reuse this login sequence by selecting the correct entry in the History tab and then
clicking Send again.
Note
If you incorrectly configure the login request you will see a response similar to the following
image:
Activity Procedure
Complete these steps:
Step 18
In the Postman window, click the plus sign to create a new tab.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 93
Step 19
In the new tab, choose POST from the HTML Methods drop-down menu.
Step 20
In the URL field, type http://192.168.R0.1/api/mo/uni.xml (replace R with your ACI Rack
Number).
Step 21
Click the Body tab; this is the location where the data that will be sent to the APIC will be
entered.
Step 22
Click the raw radio button to set the data encoding method.
Step 23
Step 24
On your Student Server, open the students file share by double-clicking the shortcut on the
desktop. This will map the S: drive to the students file share.
Step 25
Step 26
Locate your pod-specific XML file, which is named POD##-REST (replace ## with your
assigned 2-digit Pod number).
Step 27
Right-click on your pod-specific XML file name, and then select Edit with Notepad++ from
the context menu.
Step 28
The Notepad++ application will start and display the contents of your pod-specific XML file.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 94
Step 29
Copy all of the XML in the file, and then paste it into the raw section in the Postman interface.
Step 30
Step 31
You should see the following return code in the Body section beneath the Send button:
Note
If you see the return code below, you need to re-authenticate to the APIC.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 95
Step 32
Step 33
Step 34
In the Submenu bar, click ALL TENANTS. You should see a new Tenant named POD##REST.
Note
The primary point here is to stress the benefit of the open API interface to ACI. Once you
understand the ACI dictionary tree and are comfortable with a programming interface such as
Postman, it will only take seconds to accomplish significant amounts of configuration.
Step 35
Step 36
In the Navigation pane, select Tenant POD##-REST > Application Profiles > 3-Tier_App.
You will find that a three-tier application similar to the one you created previously has been
created here.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 96
Step 37
Spend a few minutes examining the objects that were created in the POD##-REST tenant using
the REST API.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 97
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Step 7
Step 8
Navigate to Pod Policies > Policies > Management Access > default.
Step 9
In the Work pane, in the HTTP section, verify that the Admin State is set to Enabled and the
Redirect is set to Disabled.
Note
Within this ACI lab environment, if these settings are incorrect, this lab exercise will not function
properly. These settings are insecure and are not recommended for a production environment.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 98
Activity Procedure
Complete these steps:
Step 10
On your Student Server, open the students file share by double-clicking the shortcut on the
desktop. This will map the S: drive to the students file share.
Step 11
Step 12
Locate your pod-specific Python script, which is named POD##-PYTHON (replace ## with
your assigned Pod number).
Step 13
Right-click on your pod-specific Python script, and then select Edit with Notepad++ from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 99
Step 14
The Notepad++ application will start and display the contents of your pod-specific Python
script.
Step 15
Review the opened Python script. This script will be used in the next Task to create a Tenant.
Activity Procedure
Complete these steps:
Step 16
Return to the File Explorer window. Right-click on your pod-specific Python script, and then
select Open with > python from the context menu.
Step 17
The Python interpreter window will appear, and it will start the Python script.
Step 18
The script will prompt you to enter the information necessary to log in to the APIC. When
prompted, enter the following information:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 100
Note
If you do not use http:// at the start of the APIC URL, the script will fail.
Step 19
The Python interpreter window will close after you enter the APIC password. This will occur
regardless of whether or not the script ran successfully.
Step 20
Step 21
Step 22
In the Submenu bar, click ALL TENANTS. You should see a new Tenant named
POD##-Python.
Note
The Python script that you used only creates a new Tenant and does not configure any other
objects or properties.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 101
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Step 7
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 8
Step 9
Right-click the Tenant POD## folder and then select Save as from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 102
Step 10
The Save As wizard will appear. Enter the values in the following table.
Field
Value
Content
Only Configuration
Scope
Subtree
Export Format
XML
Step 11
Click the DOWNLOAD button. This will save a file named tn-POD##.xml to the Downloads
folder in the Student Server.
Step 12
On your Student Server, open the students file share by double-clicking the shortcut on the
desktop. This will map the S: drive to the students file share.
Step 13
Drag and drop (move) the XML file you just created (tn-POD##.xml) from the Downloads
folder to the C:\arya folder.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 103
Activity Procedure
Complete these steps:
Step 14
On your Student Server, open a Command Prompt window by double-clicking the shortcut on
the desktop.
Step 15
The Command Prompt window will appear. If the Command Prompt window does not open
to the C:\arya directory use the cd C:\arya command to change to that directory.
Step 16
You will now use Arya to create a Python script based on the XML file that you downloaded
from the APIC GUI. Enter the following command into the Command Prompt (replace ##
with your assigned 2-digit Pod Number and replace R with your ACI Rack Number).
You may want to copy and paste the command to a text editor, modify the command, and then
copy and paste the edited command into the Command Prompt window.
Step 17
If the syntax of the command is correct, all that will happen is that you will see the command
prompt return after the Arya utility finishes running.
Note
The right angle bracket (>) between the password and pod##.py is used to pipe the Python file
that is generated by Arya. If you make a mistake on the command, it will still create a file that is
called pod##.py with zero bytes. Delete that file before troubleshooting your CLI input.
Step 18
Return to Windows Explorer. You should now see a file named pod## in the C:\arya
folder.
Step 19
Right-click the pod## file, and then select Edit with Notepad++ from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 104
Step 20
The Notepad++ application will start and open the pod##.py file for editing.
Step 21
Step 22
The Replace window will appear. Replace POD## with POD##-ARYA (replace ## with
your assigned 2-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 105
Step 23
Click the Replace All button, and then click the Close button.
Step 24
There are three lines of code that will prevent the script from running; these lines are inserted
by Arya to prevent accidental execution of the script. These three lines are near the top of the
script and start with raise RuntimeError Find these lines and delete them.
Step 25
Save the file by selecting File > Save from the Menu bar.
In Summary: You downloaded an XML encoded file with the configuration of the tenant name-GUI, where
name is your Pod airport name. You then converted this XML encoded file into a python (.py) file
using arya. Now you have customized this python file by replacing the existing tenant name
(name-GUI) with a new tenant name (name-arya). Next you will configure Cisco APIC with this
new Tenant using the Python SDK.
Activity Procedure
Complete these steps:
Step 26
Return to Windows Explorer. Verify that you are viewing the contents of the C:\arya folder.
Step 27
Right-click the pod## file, and then select Open > python from the context menu. This will
cause the python interpreter to run the script you just edited and create a new tenant named
POD##-ARYA.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 106
Step 28
Step 29
Step 30
In the Submenu bar, click ALL TENANTS. You should see a new Tenant named
POD##-ARYA. This new tenant was created by the python script you just executed, and it
should be a duplicate of the tenant POD##, including all of the policies and settings of the
original tenant.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 107
Create a Host Subnet and add a Contract to EPG in the First Tenant
Confirm the Exported Contract, create a Host Subnet in the Second Tenant and add a Consumed
Contract Interface
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Activity Procedure
Complete these steps:
Step 8
Step 9
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 108
Step 10
In the Navigation pane, expand Tenant POD## > Security Policies > Contracts.
Step 11
Right-click the Contracts folder and then select Create Contract from the context menu.
Step 12
The Create Contract wizard will appear. Enter the values in the following table.
Field
Value
Name
Scope
Global
Note
Make sure to change the scope to Global; only Global contracts may be exported to other
Tenants.
Step 13
In the Subjects subsection, click the plus sign to create a new entry. The Create Contract
Subject wizard will appear. Enter the values in the following table.
Step 14
Field
Value
Name
SUBJECT-ANY
Checked
Checked
In the Filter Chain subsection, click the plus sign to create a new entry. In the drop-down list,
select POD##/POD##-FILTER-ANY.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 109
Step 15
Step 16
Step 17
Click the SUBMIT button to complete the Create Contract wizard. You should now see the
contract you just created in the Contracts folder.
Activity Procedure
Complete these steps:
Step 18
In some of the steps in this Task you will be asked to enter your Peer Pod Number. Your Peer
Pod Number is the number of the Pod that is interacting with your Pod during this lab exercise.
Use the following table to determine your Peer Pod Number.
If your Pod Number is
11
12
12
11
13
14
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 110
14
13
15
16
16
15
17
18
18
17
19
20
20
19
21
22
22
21
23
24
24
23
25
26
26
25
Step 19
In the Navigation pane, expand Tenant POD## > Security Policies > Contracts.
Step 20
Right-click the Contracts folder and then select Export Contract from the context menu.
Step 21
The Export Contract wizard will appear. Enter the values in the following table.
Field
Value
Name
Global Contract
Tenant
Step 22
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 111
STOP!
Wait until the student configuring your Peer Pod has completed all steps up to this point
before proceeding.
Step 23
In the Navigation pane, expand Tenant POD## > Security Policies > Imported Contracts. If
the student configuring your Peer Pod has completed the steps in this lab exercise up to this
point you should see an Imported Contract named POD$$-EXPORT-CONTRACT.
Activity Procedure
Complete these steps:
Step 24
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-WEB-EPG.
Step 25
Right-click the EPG POD##-WEB-EPG folder and then select Create EPG Subnet from the
context menu.
Step 26
The Create EPG Subnet wizard. Enter the values in the following table; do NOT change any
of the values that are not listed in the following table.
Field
Value
Default Gateway IP
Checked
Unchecked
Checked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 112
Step 27
Click the SUBMIT button to complete the Create EPG Subnet wizard.
Activity Procedure
Complete these steps:
Step 28
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-WEB-EPG.
Step 29
Right-click the EPG POD##-WEB-EPG folder and then select Add Provided Contract from
the context menu.
Step 30
The Add Provided Contract wizard will appear. In the Name drop-down list select POD##/
POD##-GLOBAL-CONTRACT (replace ## with your assigned 2-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 113
Step 31
Click the SUBMIT button to complete the Add Provided Contract wizard.
Step 32
Right-click the EPG POD##-WEB-EPG folder and then select Add Consumed Contract
Interface from the context menu.
Note
Make sure to select Add Consumed Contract Interface, not Add Consumed Contract.
Step 33
The Add Consumed Contract Interface wizard will appear. In the Name drop-down list
select POD##/ POD$$-EXPORT-CONTRACT (replace ## with your assigned 2-digit Pod
Number and replace $$ with your Peer Pod Number).
Step 34
Click the SUBMIT button to complete the Add Consumed Contract Interface wizard. You
should now see two different types of Contract that are being used by the Web EPG: Contract
(used within the Application Profile) and Contract Interface (used between Tenants).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 114
Step 35
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE. You should see that the diagram representing the objects within
your Application Profile has been updated to include the new contracts.
STOP!
Wait until the student configuring your Peer Pod has completed all steps up to this point
before proceeding.
Activity Procedure
Complete these steps:
Step 36
Step 37
Step 38
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter). You should see three virtual machines which are assigned to your Pod (replace ##
with your assigned Pod number):
Step 39
Virtual Machine
IP Address
Default Gateway
Pod##-App
10.##.1.1 /24
10.##.1.254
Pod##-DB
10.##.2.1 /24
10.##.2.254
Pod##-Web
10.##.3.1 /24
10.##.3.254
Right-click the Pod##-Web VM and then select Open Console from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 115
Step 40
The console window for Pod##-Web will appear. You will see the Web servers desktop.
Step 41
Step 42
Verify that your Web Server can ping the IP address of the Peer Pod Web Server using the ping
10.$$.3.1 command (replace $$ with your Peer Pod Number).
Step 43
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 44
Step 45
Execute the show endpoint command. You should not see any new entries in this table. The
endpoints themselves have not changed, only the traffic allowed between them has changed.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 116
POD11:POD11-VRF
16/POD11:POD11-VRF
19
POD11:POD11-VRF
89
POD11:POD11-VRF
POD12:POD12-VRF
POD12:POD12-VRF
22/POD12:POD12-VRF
22/POD12:POD12-VRF
25
POD12:POD12-VRF
overlay-1
7/overlay-1
7/overlay-1
<output omitted>
vxlan-15728622
vlan-3115
vlan-3115
vlan-3114
vlan-3114
vxlan-15761386
vxlan-15761386
vlan-3127
vlan-3127
vxlan-16777209
vxlan-16777209
10.11.1.1
0050.569a.456e
0050.569a.0a8a
10.11.3.1
0050.569a.5e25
10.11.2.1
10.12.2.1
10.12.3.1
0050.569a.8f07
0050.569a.8e9b
0050.569a.5479
10.12.1.1
172.19.104.95
88f0.313c.97f2
001a.6d03.0781
B
L
L
L
L
B
B
L
L
L
L
L
tunnel4
tunnel4
eth1/33
eth1/33
eth1/33
eth1/33
tunnel4
tunnel4
tunnel4
tunnel4
eth1/33
eth1/33
lo0
eth1/1
eth1/11
Step 46
Execute the show vrf command. Again, you should not see any new entries.
Note
The output of the show vrf command is useful when you need to copy and paste a VRF name
into another command.
Step 47
VRF-ID
3
4
6
5
State
Up
Up
Up
Up
Reason
-----
Execute the show ip route vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). You should see routes to each of the subnets used by your
bridge domain as well as a route to the Peer Pod Web EPG, 10.$$.3.0/24. This prefix was
leaked into your Pod VRF by the imported global contract.
Step 48
Execute the show ip route vrf POD$$:POD$$-VRF command (replace $$ with your Peer
Pod Number). You should see routes to each of the subnets used by your Peer Pods bridge
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 117
domain as well as a route to your Pods Web EPG, 10.##.3.0/24. This prefix was leaked into
your Peer Pods VRF by the exported global contract.
Leaf-1# show ip route vrf POD$$:POD$$-VRF
IP Route Table for VRF "POD$$:POD$$-VRF"
'*' denotes best ucast next-hop
'**' denotes best mcast next-hop
'[x/y]' denotes [preference/metric]
'%<string>' in via output denotes VRF <string>
10.##.3.0/24, ubest/mbest: 1/0, attached, direct, pervasive
*via 172.19.64.65%overlay-1, [1/0], 00:06:42, static
10.$$.1.0/24, ubest/mbest: 1/0, attached, direct, pervasive
*via 172.19.64.65%overlay-1, [1/0], 00:04:35, static
10.$$.1.254/32, ubest/mbest: 1/0, attached
*via 10.$$.1.254, vlan14, [1/0], 04:51:17, local, local
10.$$.2.0/24, ubest/mbest: 1/0, attached, direct, pervasive
*via 172.19.64.65%overlay-1, [1/0], 00:04:35, static
10.$$.2.254/32, ubest/mbest: 1/0, attached
*via 10.$$.2.254, vlan14, [1/0], 04:51:17, local, local
10.$$.3.0/24, ubest/mbest: 1/0, attached, direct, pervasive
*via 172.19.64.65%overlay-1, [1/0], 00:04:35, static
10.$$.3.254/32, ubest/mbest: 1/0, attached
*via 10.$$.3.254, vlan14, [1/0], 04:51:17, local, local
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 118
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Note
The first step in this configuration is to create an Attachable Access Entity Profile (AEP) for the
interface connected to the external switch. The AEP will be the point to which you connect the
external routed domain you will create later in this lab exercise.
Note
If you attempt to configure an external bridged or routed network without attaching it to an AEP
you will get inconsistent results as well as Faults generated within the APIC.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 119
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 8
Step 9
Right-click the Attachable Access Entity Profiles folder and then select Create Attachable
Access Entity Profile from the context menu.
Step 10
The Create Attachable Access Entity Profile wizard will appear. In STEP 1 > Profile, enter
the values in the following table.
Field
Value
Name
L3-LAB-AEP
Checked
Step 11
Click the NEXT button. In STEP 2 > Association to Interfaces, do not make any changes.
Step 12
Click the FINISH button to complete the Create Attachable Access Entity Profile wizard.
Note
The next step is to create an Interface Policy Group for each Fabric. The Interface Policy Group
defines how an interface on a leaf switch should operate (e.g. link speed), and the Interface
Policy Group is also the point where you indicate which AEP will use the interface.
Note
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 120
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 13
Step 14
Right-click the Policy Groups folder and then select Create Access Port Policy Group from
the context menu.
Step 15
The Create Access Port Policy Group wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
L3-LAB-INTERFACE-POLICY-GROUP
CDP Policy
LLDP Policy
L3-LAB-AEP
Step 16
Click the SUBMIT button to complete the Create Access Port Policy Group wizard.
Note
The next step is to create an Interface Profile for each Fabric. The Interface Profile will identify
the specific interface number(s) on the leaf switches that will use the associated Interface Policy
Group. The Interface Profile does not identify the leaf switches where the interfaces are located;
the leaf switches are identified in the Switch Profile (created later in this lab exercise).
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 121
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 17
Step 18
Right-click the Profiles folder and then select Create Interface Profile from the context menu.
Step 19
The Create Interface Profile wizard will appear. In the Name field, type L3-LABINTERFACE-PROFILE.
Step 20
In the Interface Selectors subsection, click the plus sign to create a new entry. The Create
Access Port Selector wizard will appear. Enter the values in the following table; do NOT
change any of the values that are not listed in the following table.
Field
Value
Name
INTERFACE-SELECTOR
Interface ID
1/6
L3-LAB-INTERFACE-POLICY-GROUP
Step 21
Click the OK button to complete the Create Access Port Selector wizard.
Step 22
Click the SUBMIT button to complete the Create Interface Profile wizard.
Note
The next step is to create a Switch Profile for each Fabric. The Switch Profile identifies the
specific nodes (leaf switches) to which the associated Interface Profile should be applied. At the
end of this step, assuming everything was configured properly, the physical interface on the leaf
switch should be in an up state.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 122
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 23
Step 24
Right-click the Profiles folder and then select Create Switch Profile from the context menu.
Step 25
The Create Switch Profile wizard will appear. In STEP 1 > Profile, in the Name field, type
L3-LAB-SWITCH-PROFILE.
Step 26
In the Switch Selectors subsection, click the plus sign to create a new entry. Enter the values in
the following table.
Field
Value
Name
SWITCH-SELECTOR
Blocks
103
Step 27
Step 28
Click the NEXT button. In STEP 2 > Associations, in the Interface Selector Profiles pane,
select L3-LAB-INTERFACE-PROFILE.
Step 29
Click the FINISH button to complete the Create Switch Profile wizard.
Page 123
Activity Procedure
Complete these steps:
Note
All students should perform this Task and all remaining Tasks in this lab exercise.
Step 30
Step 31
Step 32
Step 33
Step 34
Right-click the VLAN folder and then select Create VLAN Pool from the context menu.
Step 35
The Create VLAN Pool wizard will appear. Enter the values in the following table.
Field
Value
Name
Allocation
Mode
Static Allocation
Step 36
In the Encap Blocks subsection, click the plus sign to create a new VLAN range. Enter the
values in the following table.
Field
Value
Range (From)
Range (To)
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 124
Step 37
Step 38
Click the SUBMIT button to complete the Create VLAN Pool wizard.
Note
In this step you will create an External Routed Domain which will be used in subsequent lab
exercises. An External Routed Domain is required in order to configure layer 3 connectivity to
external networks.
Activity Procedure
Complete these steps:
Step 39
Step 40
Step 41
Step 42
Right-click the External Routed Domains folder and then select Create Layer 3 Domain
from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 125
Step 43
The Create Layer 3 Domain wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
L3-LAB-AEP
VLAN Pool
Step 44
Click the SUBMIT button to complete the Create Layer 3 Domain wizard.
Note
At this point the physical interface of the leaf switch connected to the external network is ready
for use. Next, you will configure the policies necessary to route traffic through this interface.
Note
The next step is to configure an OSPF Interface Policy, which defines attributes of how an
interface should use OSPF. These attributes correspond to those you would configure on an
interface in IOS.
Activity Procedure
Complete these steps:
Note
Step 45
Step 46
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 47
In the Navigation pane, expand Tenant POD## > Networking > Protocol Policies > OSPF
Interface.
Step 48
Right-click the OSPF Interface folder and then select Create OSPF Interface Policy from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 126
Step 49
The Create OSPF Interface Policy wizard will appear. Enter the values in the following table;
do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Network Type
Broadcast
Checked
Step 50
Click the SUBMIT button to complete the Create OSPF Interface Policy wizard.
Activity Procedure
Complete these steps:
Step 51
In the Navigation pane, expand Tenant POD## > Networking >External Routed Networks.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 127
Step 52
Right-click the External Routed Networks folder and then select Create Routed Outside
from the context menu.
Step 53
The Create Routed Outside wizard will appear. In STEP 1 > Identity, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
VRF
External Routed
Domain
OSPF
Checked
OSPF Area ID
NSSA area
Step 54
In the Nodes And Interfaces Protocol Profiles subsection, click the plus sign to create a new
entry. The Create Node Profile wizard will appear. In the Name field type POD##LOGICAL-NODE-PROFILE (replace ## with your assigned 2-digit Pod Number).
Step 55
In the Nodes subsection, click the plus sign to create a new entry. The Select Node wizard will
appear. Enter the values in the following table; do NOT change any of the values that are not
listed in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 128
Field
Value
Node ID
Router ID
Checked
Step 56
Step 57
In the OSPF Interface Profiles subsection, click the plus sign to create a new entry. The
Create Interface Profile wizard will appear. Enter the values in the following table.
Field
Value
Name
Authentication
Type
MD5
Authentication Key
1234QWer
OSPF Policy
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 129
Step 58
Step 59
In the SVI Interfaces subsection, click the plus sign to create a new entry. The Select SVI
Interface wizard will appear. Enter the values in the following table; do NOT change any of the
values that are not listed in the following table.
Field
Value
Path Type
Port
Path
Encap
IP Address
MTU (bytes)
1500
Step 60
Step 61
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 130
Step 62
Step 63
Step 64
In STEP 2 > External EPG Networks, in the External EPG Networks subsection, click the
plus sign to create a new entry. The Create External Network wizard will appear. In the
Name field type POD##-ROUTED-EXTERNAL-EPG (replace ## with your assigned 2digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 131
Step 65
In the Subnet subsection, click the plus sign to create a new entry. The Create Subnet wizard
will appear. In the IP Address field type 10.1##.0.0/16 (replace ## with your assigned 2-digit
Pod Number).
Step 66
Step 67
In the Subnet subsection, click the plus sign to create a new entry. The Create Subnet wizard
will appear. In the IP Address field type 172.16.##.0/24 (replace ## with your assigned 2digit Pod Number).
Step 68
Step 69
Step 70
Click the FINISH button to complete the Create Routed Outside wizard.
Task 9: Configure Contracts between the Web EPG and the External
Routed Network
In this task, you will configure Contracts to allow traffic to flow between the Web EPG and the External
Routed Network EPG
Activity Procedure
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 132
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-WEB-EPG > Contracts.
Step 72
Right-click the Contracts folder and then select Add Provided Contract from the context
menu.
Step 73
The Add Provided Contract wizard will appear. In the Contract field, select POD##/POD##CONTRACT-ANY from the drop-down list.
Step 74
Click the SUBMIT button to complete the Add Provided Contract wizard.
Step 75
In the Navigation pane, expand Tenant POD## > Networking > External Routed Networks
> POD##-EXTERNAL-ROUTED-NETWORK > Networks > POD##-ROUTEDEXTERNAL-EPG.
Step 76
In the Work panel, click the Policy tab and then click the Contracts sub-tab.
Step 77
In the Consumed Contracts pane, click the plus sign to create a new entry. In the NAME field,
select POD##/POD##-CONTRACT-ANY from the drop-down list.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 133
Step 78
Task 10: Associate the External Routed Network to the Bridge Domain
In this task, you will configure the bridge domain within your Tenant to use the external routed network.
Activity Procedure
Complete these steps:
Step 79
In the Navigation pane, expand Tenant POD## > Networking > Bridge Domains > POD##BD.
Step 80
In the Work panel, click the Policy tab and then click the L3 Configurations sub-tab.
Step 81
In the Work pane, in the Associated L3 Outs subsection, click the plus sign to create a new
entry. In the L3 OUT field, select POD##/POD##-EXTERNAL-ROUTED-NETWORK
from the drop-down list
Step 82
Click the UPDATE button. A Policy Usage Warning will appear indicating the other objects
that will be affected by the changes.
Step 83
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 134
Step 84
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE and then click the Topology tab in the Work pane. You should
now see the updated diagram for the application profile and that it includes the new
connectivity to the external routed network.
Activity Procedure
Complete these steps:
Step 85
In the Navigation pane, expand Tenant POD## > Networking > Bridge Domains > POD##BD > Subnets > 10.##.1.254/24.
Step 86
Step 87
Click the SUBMIT button. A Policy Usage Warning will appear indicating the other objects
that will be affected by the changes.
Step 88
Step 89
Repeat the previous four steps to change the scope to Advertised Externally for the subnet
10.##.2.254/24.
Step 90
Repeat the previous four steps to change the scope to Advertised Externally for the subnet
10.##.3.254/24.
Activity Procedure
Complete these steps:
Step 91
In the Navigation pane, expand Tenant POD## > Networking > External Routed Networks
> POD##-EXTERNAL-ROUTED-NETWORK > Logical Node Profiles > POD##LOGICAL-NODE-PROFILE > Configured Nodes > topology/pod-1/node-103 > OSPF for
VRF POD##:POD##-VRF. You should see one OSPF neighbor to the external router listed.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 135
Step 92
In the Navigation pane, expand OSPF for VRF POD##:POD##-VRF > Routes. You
should see several routes being advertised by the external routers, which include the following:
10.1##.7.1/32
10.1##.8.1/32
10.1##.9.1/32
Step 93
From your Student Server desktop, start a PuTTY session with Leaf-2. There should be a
shortcut on the desktop for Leaf-2.
Step 94
Step 95
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 136
Note
The output of the show vrf command is useful when you need to copy and paste a VRF name
into another command.
Step 96
VRF-ID
3
4
6
5
State
Up
Up
Up
Up
Reason
-----
Execute the show ip route ospf vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). You should see routes to the following subnets:
10.1##.7.1/32
10.1##.8.1/32
10.1##.9.1/32
Step 97
Note
When testing connectivity through the fabric, the iping command will generate traffic and use the
VXLAN overlay as needed; the ping command does not use the VXLAN overlay.
Step 98
Execute the show endpoint vrf POD##:POD##-VRF detail command (replace ## with your
assigned 2-digit Pod Number). This command will display the endpoints identified by the APIC
within your VRF. You should see an entry with the IP address of ##.##.##.## ; this indicates
that the external devices are identified as a single endpoint.
S - static
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 137
V - vpc-attached
p - peer-aged
L - local
M - span
s - static-arp
B - bounce
+---------------+---------------+-----------------+--------------+-------------+-----------------------------+
VLAN/
Encap
MAC Address
MAC Info/
Interface
Endpoint Group
Domain
VLAN
IP Address
IP Info
Info
+---------------+---------------+-----------------+--------------+-------------+-----------------------------+
POD##:POD##-VRF
##.##.##.## L
19
vlan-3101
0050.568c.a008 LV
po1
POD##:POD##-APPLICATION-PROFILE:POD##-APP-EPG
POD##:POD##-VRF
vlan-3101
10.##.1.1 LV
20
vlan-3102
0050.568c.a369 LpV
po1
POD##:POD##-APPLICATION-PROFILE:POD##-DB-EPG
POD##:POD##-VRF
vlan-3102
10.##.2.1 LV
21
vlan-3134
0050.568c.e660 LpV
po1
POD##:POD##-APPLICATION-PROFILE:POD##-WEB-EPG
POD##:POD##-VRF
vlan-3134
10.##.3.1 LV
+------------------------------------------------------------------------------+
Endpoint Summary
+------------------------------------------------------------------------------+
Total number of Local Endpoints
: 4
Total number of Remote Endpoints
: 0
Total number of Peer Endpoints
: 0
Total number of vPC Endpoints
: 3
Total number of non-vPC Endpoints
: 1
Total number of MACs
: 3
Total number of VTEPs
: 0
Total number of Local IPs
: 4
Total number of Remote IPs
: 0
Total number All EPs
: 4
Step 99
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 100
Step 101
Execute the show ip route ospf vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). You will not see any routes as OSPF is not running on Leaf-1.
Step 102
Execute the show ip route bgp vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). You will see the routes to the external networks as prefixes that
have been redistributed into the BGP routing process.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 138
Step 103
Step 104
Step 105
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter). You should see three virtual machines which are assigned to your Pod (replace ##
with your assigned Pod number):
Virtual Machine
IP Address
Default Gateway
Pod##-App
10.##.1.1 /24
10.##.1.254
Pod##-DB
10.##.2.1 /24
10.##.2.254
Pod##-Web
10.##.3.1 /24
10.##.3.254
Step 106
Right-click the Pod##-Web VM and then select Open Console from the context menu.
Step 107
The console window for Pod##-Web will appear. You will see the Web servers desktop.
Step 108
Step 109
Verify that your Web Server can ping the IP address of the first route learned via OSPF using
the ping 10.1##.7.1 command (replace ## with your assigned 2-digit Pod Number).
Step 110
Verify that your Web Server can ping the IP address of the second route learned via OSPF
using the ping 10.1##.8.1 command (replace ## with your assigned 2-digit Pod Number).
Step 111
Verify that your Web Server can ping the IP address of the third route learned via OSPF using
the ping 10.1##.9.1 command (replace ## with your assigned 2-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 139
Task 0: Log in to the APIC Controller and the VMware vSphere Client
In this task, you will log in to the APIC controller using the graphical user interface (GUI) and you will log
in to your assigned VMware vCenter server using the VMware vSphere Client.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Note
The first step in this configuration is to create an Attachable Access Entity Profile (AEP) for the
interface connected to the external switch. The AEP will be the point to which you connect the
external bridged domain you will create later in this lab exercise.
Note
If you attempt to configure an external bridged or routed network without attaching it to an AEP
you will get inconsistent results as well as Faults generated within the APIC.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 140
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 8
Step 9
Right-click the Attachable Access Entity Profiles folder and then select Create Attachable
Access Entity Profile from the context menu.
Step 10
The Create Attachable Access Entity Profile wizard will appear. In STEP 1 > Profile, enter
the values in the following table.
Field
Value
Name
L2-LAB-AEP
Checked
Step 11
Click the NEXT button. In STEP 2 > Association to Interfaces, do not make any changes.
Step 12
Click the FINISH button to complete the Create Attachable Access Entity Profile wizard.
Note
The next step is to create an Interface Policy Group for each Fabric. The Interface Policy Group
defines how an interface on a leaf switch should operate (e.g. link speed), and the Interface
Policy Group is also the point where you indicate which AEP will use the interface.
Note
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 13
Step 14
Right-click the Policy Groups folder and then select Create Access Port Policy Group from
the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 141
Step 15
The Create Access Port Policy Group wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
L2-LAB-INTERFACE-POLICY-GROUP
CDP Policy
LLDP Policy
L2-LAB-AEP
Step 16
Click the SUBMIT button to complete the Create Access Port Policy Group wizard.
Note
The next step is to create an Interface Profile for each Fabric. The Interface Profile will identify
the specific interface number(s) on the leaf switches that will use the associated Interface Policy
Group. The Interface Profile does not identify the leaf switches where the interfaces are located;
the leaf switches are identified in the Switch Profile (created later in this lab exercise).
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 17
Step 18
Right-click the Profiles folder and then select Create Interface Profile from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 142
Step 19
The Create Interface Profile wizard will appear. In the Name field, type L2-LABINTERFACE-PROFILE.
Step 20
In the Interface Selectors subsection, click the plus sign to create a new entry. The Create
Access Port Selector wizard will appear. Enter the values in the following table; do NOT
change any of the values that are not listed in the following table.
Field
Value
Name
INTERFACE-SELECTOR
Interface ID
1/5
L2-LAB-INTERFACE-POLICY-GROUP
Step 21
Click the OK button to complete the Create Access Port Selector wizard.
Step 22
Click the SUBMIT button to complete the Create Interface Profile wizard.
Note
The next step is to create a Switch Profile for each Fabric. The Switch Profile identifies the
specific nodes (leaf switches) to which the associated Interface Profile should be applied. At the
end of this step, assuming everything was configured properly, the physical interface on the leaf
switch should be in an up state.
STOP!
This Task will be performed by the Instructor; students do NOT perform this Task.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 143
Activity Procedure
Complete these steps:
STOP!
The following steps will be performed by the Instructor; students do NOT perform this
Task.
Step 23
Step 24
Right-click the Profiles folder and then select Create Switch Profile from the context menu.
Step 25
The Create Switch Profile wizard will appear. In STEP 1 > Profile, in the Name field, type
L2-LAB-SWITCH-PROFILE.
Step 26
In the Switch Selectors subsection, click the plus sign to create a new entry. Enter the values in
the following table.
Field
Value
Name
SWITCH-SELECTOR
Blocks
103
Step 27
Step 28
Click the NEXT button. In STEP 2 > Associations, in the Interface Selector Profiles pane,
select L2-LAB-INTERFACE-PROFILE.
Step 29
Click the FINISH button to complete the Create Switch Profile wizard.
Step 30
From your Student Server desktop, start a PuTTY session with Leaf-2. There should be a
shortcut on the desktop for Leaf-2.
Step 31
Step 32
Execute the show interface e1/6 brief command. You should see that your assigned interface is
in an up state.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 144
Activity Procedure
Complete these steps:
Note
All students should perform this Task and all remaining Tasks in this lab exercise.
Step 33
Step 34
Step 35
Step 36
Step 37
Right-click the VLAN folder and then select Create VLAN Pool from the context menu.
Step 38
The Create VLAN Pool wizard will appear. Enter the values in the following table.
Field
Value
Name
Allocation
Mode
Static Allocation
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 145
Step 39
In the Encap Blocks subsection, click the plus sign to create a new VLAN range. Enter the
values in the following table.
Field
Value
Range (From)
Range (To)
Step 40
Step 41
Click the SUBMIT button to complete the Create VLAN Pool wizard.
Note
In this step you will create an External Bridged Domain which will be used in subsequent lab
exercises. An External Bridged Domain is required in order to configure layer 2 connectivity to
external networks.
Activity Procedure
Complete these steps:
Step 42
Step 43
Step 44
Step 45
Right-click the External Bridged Domains folder and then select Create Layer 2 Domain
from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 146
Step 46
The Create Layer 2 Domain wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Name
L2-LAB-AEP
VLAN Pool
Step 47
Click the SUBMIT button to complete the Create Layer 2 Domain wizard.
Activity Procedure
Complete these steps:
Step 48
In the Navigation pane, expand Tenant POD## > Networking >External Bridged Networks.
Step 49
Right-click the External Bridged Networks folder and then select Create Bridged Outside
from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 147
Step 50
The Create Bridged Outside wizard will appear. In STEP 1 > Identity, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Bridge Domain
Encap
Path Type
Port
Path
Node-103/eth1/5
Note
Make sure to click the ADD button after you select the path; the path you select must appear in
the lower portion of the wizard.
Step 51
Step 52
In STEP 2 > External EPG Networks, in the External EPG Networks subsection, click the
plus sign to create a new entry.
Step 53
The Create External Network wizard will appear. In the Name field type POD##EXTERNAL-BRIDGED-EPG (replace ## with your assigned 2-digit Pod Number).
Step 54
Click the SUBMIT button to complete the Create External Network wizard.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 148
Step 55
Click the FINISH button to complete the Create Bridged Outside wizard.
Task 8: Configure Contracts between the Web EPG and the External
Bridged Network
In this task, you will configure Contracts to allow traffic to flow between the Web EPG and the External
Bridged Network EPG.
Activity Procedure
Complete these steps:
Step 56
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-WEB-EPG > Contracts.
Step 57
Right-click the Contracts folder and then select Add Provided Contract from the context
menu.
Step 58
The Add Provided Contract wizard will appear. In the Contract field, select POD##/POD##CONTRACT-ANY from the drop-down list.
Step 59
Click the SUBMIT button to complete the Add Provided Contract wizard.
Step 60
In the Navigation pane, expand Tenant POD## > Networking > External Bridged Networks
> POD##-EXTERNAL-BRIDGED-NETWORK > Networks > POD##-EXTERNALBRIDGED-EPG.
Step 61
Step 62
In the Consumed Contracts pane, click the plus sign to create a new entry. In the NAME field,
select POD##-CONTRACT-ANY from the drop-down list.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 149
Step 63
Step 64
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE.
Step 65
In the Work pane, click the Policy tab. You should see that the diagram representing the objects
within your Application Profile has been updated to include the new contracts.
Task 9: Verify That the Web EPG Can Communicate with the External
Bridged Domain
In this task, you will verify that the Web Server in your Web EPG can successfully communicate with a
device in the External Bridged Domain.
Activity Procedure
Complete these steps:
Step 66
Step 67
Step 68
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter). You should see three virtual machines which are assigned to your Pod (replace ##
with your assigned Pod number):
Step 69
Virtual Machine
IP Address
Default Gateway
Pod##-App
10.##.1.1 /24
10.##.1.254
Pod##-DB
10.##.2.1 /24
10.##.2.254
Pod##-Web
10.##.3.1 /24
10.##.3.254
Right-click the Pod##-Web VM and then select Open Console from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 150
Step 70
The console window for Pod##-Web will appear. You will see the Web servers desktop.
Step 71
Step 72
There is a device in the external bridged network that is configured to use VLAN ##1 with the
IP address 10.##.3.2 (this is the same subnet used by your Web Server virtual machine). Verify
that your Web Server can ping this IP address using the ping 10.##.3.2 command (replace ##
with your assigned 2-digit Pod Number).
Step 73
From your Student Server desktop, start a PuTTY session with Leaf-2. There should be a
shortcut on the desktop for Leaf-2.
Step 74
Step 75
Note
The output of the show vrf command is useful when you need to copy and paste a VRF name
into another command.
Step 76
VRF-ID
3
4
6
5
State
Up
Up
Up
Up
Reason
-----
Execute the show endpoint vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). This command will display the endpoints identified by the APIC
within your VRF. You should see an entry with the IP address of 10.##.3.2 .
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 151
+---------------+---------------+-----------------+--------------+-------------+-----------------------------+
POD##:POD##-VRF
##.##.##.## L
15
vlan-3##7
0050.569a.456e L
eth1/34
POD##:POD##-VRF
vlan-3##7
10.##.1.1 L
16
vlan-3##4
0050.569a.0a8a O
eth1/33
POD##:POD##-VRF
vlan-3##4
10.##.3.1 O
17
vlan-3##1
0050.569a.5e25 O
eth1/33
POD##:POD##-VRF
vlan-3##1
10.##.2.1 O
24
vlan-2##
0018.1987.1d42 L
eth1/5
POD##:POD##-VRF
vlan-2##
10.##.3.2 L
+------------------------------------------------------------------------------+
Endpoint Summary
+------------------------------------------------------------------------------+
Total number of Local Endpoints
: 3
Total number of Remote Endpoints
: 0
Total number of Peer Endpoints
: 2
Total number of vPC Endpoints
: 0
Total number of non-vPC Endpoints
: 3
Total number of MACs
: 4
Total number of VTEPs
: 0
Total number of Local IPs
: 3
Total number of Remote IPs
: 2
Total number All EPs
: 5
Step 77
Execute the show vlan extended command. You should see a new fabric VLAN that has been
created that is associated with the port connected to the external bridge domain VLAN.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 152
To distinguish the extending an EPG method from the extending the bridge domain method
the terms bare metal network and bare metal server will be used in this lab exercise. These
terms refer to devices that are directly or indirectly connected to a leaf switch at layer 2. The
term bare metal indicates that the server is not a hypervisor/host (no virtualization is present)
and the Windows/Linux/UNIX operating system is installed directly onto the hardware. These
terms are found in many of the Cisco ACI documents.
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Step 6
From your Student Server desktop, start the VMware vSphere Client. Log in to your assigned
vCenter server using the following credentials:
Username: root
Step 7
At this point you should see the vCenter-@ - vSphere Client window.
Page 153
In this task, you will create VLAN pool that will be used by the physical domain you will create in a
subsequent Task.
Activity Procedure
Complete these steps:
Step 8
Step 9
Step 10
Step 11
Step 12
Right-click the VLAN folder and then select Create VLAN Pool from the context menu.
Step 13
The Create VLAN Pool wizard will appear. Enter the values in the following table.
Field
Value
Name
Allocation Mode
Static Allocation
Step 14
In the Encap Blocks subsection, click the plus sign to create a new VLAN range. Enter the
values in the following table.
Field
Value
Range (From)
Range (To)
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 154
Step 15
Step 16
Click the SUBMIT button to complete the Create VLAN Pool wizard.
Activity Procedure
Complete these steps:
Step 17
Step 18
Step 19
Step 20
Right-click the Physical Domains folder and then select Create Physical Domain from the
context menu.
Step 21
The Create Physical Domain wizard will appear. Enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 155
Field
Value
Name
VLAN Pool
Step 22
Click the SUBMIT button to complete the Create Physical Domain wizard.
Activity Procedure
Complete these steps:
Step 23
Step 24
Step 25
Step 26
Right-click the Attachable Access Entity Profiles folder and then select Create Attachable
Access Entity Profile from the context menu.
Step 27
The Create Attachable Access Entity Profile wizard will appear. In STEP 1 > PROFILE,
enter the values in the following table.
Field
Value
Name
Checked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 156
Step 28
Step 29
Step 30
Click the NEXT button. In STEP 2 > Association to Interfaces, do not make any changes.
Step 31
Click the FINISH button to complete the Create Attachable Access Entity Profile wizard.
Activity Procedure
Complete these steps:
Step 32
Step 33
Right-click the Policy Groups folder and then select Create Access Port Policy Group from
the context menu.
Step 34
The Create Access Port Policy Group wizard will appear. Enter the values in the following
table; do NOT change any of the values that are not listed in the following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 157
Field
Value
Name
CDP Policy
LLDP Policy
Step 35
Click the SUBMIT button to complete the Create Access Port Policy Group wizard.
Activity Procedure
Complete these steps:
Step 36
Step 37
Right-click the Profiles folder and then select Create Interface Profile from the context menu.
Step 38
The Create Interface Profile wizard will appear. In the Name field, type POD##-BAREMETAL-INTERFACE-PROFILE (replace ## with your assigned two-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 158
Step 39
In the Interface Selectors subsection, click the plus sign to create a new entry. The Create
Access Port Selector wizard will appear. Enter the values in the following table; do NOT
change any of the values that are not listed in the following table.
Field
Value
Name
INTERFACE-SELECTOR
Interface ID
Interface Policy
Group
Step 40
Click the OK button to complete the Create Access Port Selector wizard.
Step 41
Click the SUBMIT button to complete the Create Interface Profile wizard.
Activity Procedure
Complete these steps:
Step 42
Step 43
Right-click the Profiles folder and then select Create Switch Profile from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 159
Step 44
The Create Switch Profile wizard will appear. In STEP 1 > Profile, in the Name field, type
POD##-BARE-METAL-SWITCH-PROFILE (replace ## with your assigned two-digit
Pod Number).
Step 45
In the Switch Selectors subsection, click the plus sign to create a new entry. Enter the values in
the following table.
Field
Value
Name
SWITCH-SELECTOR
Blocks
101
Step 46
Step 47
Click the NEXT button. In STEP 2 > Associations, in the Interface Selector Profiles pane,
select POD##-BARE-METAL-INTERFACE-PROFILE (replace ## with your assigned
two-digit Pod Number).
Step 48
Click the FINISH button to complete the Create Switch Profile wizard.
Activity Procedure
Complete these steps:
Step 49
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 160
Step 50
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 51
In the Navigation pane, expand Tenant POD## > Networking > Bridge Domains.
Step 52
Right-click the Bridge Domains folder and then select Create Bridge Domain from the
context menu.
Step 53
The Create Bridge Domain wizard will appear. In STEP 1 > Main, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
VRF
Step 54
Click the NEXT button. In STEP 2 > L3 Configurations, in the Subnets subsection, click the
plus sign to start the Create Subnet wizard.
Step 55
The Create Subnet wizard will appear. Enter the values in the following table; do NOT change
any of the values that are not listed in the following table.
Field
Value
Gateway IP
checked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 161
Step 56
Step 57
Click the NEXT button. In STEP 3 > Advanced/Troubleshooting, do not make any changes.
Step 58
Click the FINISH button to complete the Create Bridge Domain wizard.
Activity Procedure
Complete these steps:
Step 59
Step 60
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 61
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs.
Step 62
Right-click the Application EPGs folder and then select Create Application EPG from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 162
Step 63
The Create Application EPG wizard will appear. In STEP 1 > Identity, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
Name
Bridge Domain
Checked
Step 64
Click the NEXT button. In STEP 2 > Leaves/Paths, in the Physical Domain drop-down list,
select POD##-BARE-METAL-PHYSICAL-DOMAIN (replace ## with your assigned twodigit Pod Number).
Step 65
Click the FINISH button to complete the Create Application EPG wizard.
Step 66
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-BARE-METAL-EPG >
Static Bindings (Paths).
Step 67
Right-click the Static Bindings (Paths) folder and then select Deploy Static EPG on PC,
VPC, or Interface from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 163
Step 68
The Deploy Static EPG on PC, VPC, or Interface wizard will appear. Enter the values in the
following table.
Field
Value
Path Type
Port
Path
Encap
Deployment Immediacy
Immediate
Mode
Trunk
Step 69
Click the SUBMIT button to complete the Deploy Static EPG on PC, VPC, or Interface
wizard.
Activity Procedure
Complete these steps:
Step 70
In the Navigation pane, expand Tenant POD## > Security Policies > Contracts.
Step 71
Right-click the Contracts folder and then select Create Contract from the context menu.
Step 72
The Create Contract wizard will appear. In the Name field type POD##-CONTRACT-DBBARE-METAL (replace ## with your assigned 2-digit Pod Number).
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 164
Step 73
In the Subjects subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
SUBJECT-ANY
Checked
Checked
Step 74
In the Filter Chain subsection, click the plus sign to create a new entry. In the drop-down list,
select POD##-FILTER-ANY.
Step 75
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 165
Step 76
Click the SUBMIT button to complete the Create Contract wizard. You should now see the
contract you just created in the Contracts folder.
Task 10: Configure Contracts between the DB EPG and the Bare Metal
EPG
In this task, you will apply the Bare Metal Contract to allow traffic to flow between the DB EPG and the
Bare Metal EPG.
Activity Procedure
Complete these steps:
Step 77
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-BARE-METAL-EPG >
Contracts.
Step 78
Right-click the Contracts folder and then select Add Provided Contract from the context
menu.
Step 79
The Add Provided Contract wizard will appear. In the Contract field, select POD##/POD##CONTRACT-DB-BARE-METAL from the drop-down list.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 166
Step 80
Click the SUBMIT button to complete the Add Provided Contract wizard.
Step 81
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-DB-EPG > Contracts.
Step 82
Right-click the Contracts folder and then select Add Consumed Contract from the context
menu.
Step 83
The Add Consumed Contract wizard will appear. In the Name drop-down list select POD##/
POD##-CONTRACT- BARE-METAL (replace ## with your assigned 2-digit Pod
Number).
Step 84
Click the SUBMIT button to complete the Add Consumed Contract wizard.
Step 85
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE.
Step 86
In the Work pane, click the Policy tab. You should see that the diagram representing the objects
within your Application Profile has been updated to include the new contracts.
Page 167
In this task, you will verify that your Pod DB server can communicate with the bare metal file server
connected to the leaf switch.
Activity Procedure
Complete these steps:
Step 87
Step 88
Step 89
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter). You should see three virtual machines which are assigned to your Pod (replace ##
with your assigned Pod number):
Virtual Machine
IP Address
Default Gateway
Pod##-App
10.##.1.1 /24
10.##.1.254
Pod##-DB
10.##.2.1 /24
10.##.2.254
Pod##-Web
10.##.3.1 /24
10.##.3.254
Step 90
Right-click the Pod##-DB VM and then select Open Console from the context menu.
Step 91
The console window for Pod##-DB will appear. You will see the DB servers desktop.
Step 92
Step 93
Verify that your DB Server can ping the bare metal file server using the ping 10.##.4.1
command (replace ## with your assigned 2-digit Pod Number).
Step 94
From your Student Server desktop, start a PuTTY session with Leaf-1. There should be a
shortcut on the desktop for Leaf-1.
Step 95
Step 96
Note
The output of the show vrf command is useful when you need to copy and paste a VRF name
into another command.
Step 97
VRF-ID
3
4
6
5
State
Up
Up
Up
Up
Reason
-----
Execute the show endpoint vrf POD##:POD##-VRF command (replace ## with your
assigned 2-digit Pod Number). This command will display the endpoints identified by the APIC
within your VRF. You should see an entry with the IP address of 10.##.4.1 .
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 168
VLAN/
Encap
MAC Address
MAC Info/
Interface
Domain
VLAN
IP Address
IP Info
+-----------------------------------+---------------+-----------------+-------------+-------------+
15
vlan-3##4
0050.569a.5e25 L
eth1/33
POD##:POD##-VRF
vlan-3##4
10.##.2.1 L
16
vlan-3##0
0050.569a.0a8a L
eth1/33
POD##:POD##-VRF
vlan-3##0
10.##.3.1 L
17
vlan-3##5
0050.569a.456e O
eth1/34
POD##:POD##-VRF
vlan-3##5
10.##.1.1 O
23
vlan-4##
0016.c714.6b52 L
eth1/##
POD##:POD##-VRF
vlan-4##
10.##.4.1 L
+------------------------------------------------------------------------------+
Endpoint Summary
+------------------------------------------------------------------------------+
Total number of Local Endpoints
: 3
Total number of Remote Endpoints
: 0
Total number of Peer Endpoints
: 1
Total number of vPC Endpoints
: 0
Total number of non-vPC Endpoints
: 3
Total number of MACs
: 4
Total number of VTEPs
: 0
Total number of Local IPs
: 3
Total number of Remote IPs
: 1
Total number All EPs
: 4
Step 98
Execute the show vlan extended command. You should see a new fabric VLAN that has been
created that is associated with the port connected to the bare metal server.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 169
ASAv
Security
Level
IP Address
Contract
Type
L4-L7
Device
Interface
Name
Network
Adapter 1
Management0/0
192.168.R0.<##+50>
N/A
N/A
Network
Adapter 2
GigabitEthernet0/0
50
10.##.4.254
Consumer
Outside
Network
Adapter 3
GigabitEthernet0/1
100
10.##.2.254
Provider
Inside
ASAv VM
Network
Adapter
Function
Profile
Interface
Name
N/A
externalIf
internalIf
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 170
Step 5
Note
This Task will be performed by the Instructor; students do NOT perform this Task.
Activity Procedure
Complete these steps:
Note
This Task will be performed by the Instructor; students do NOT perform this Task.
Step 6
Step 7
Step 8
In the Navigation pane, right-click the L4-L7 Service Device Types folder, and then select
Import Device Package from the context menu.
Step 9
The Import Device Package dialog window will appear. Click the BROWSE button.
Step 10
Step 11
Step 12
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 171
Step 13
Click the SUBMIT button. It will take a few seconds for the Device Package to be imported.
Step 14
When the import process is complete you will see a new entry under the L4-L7 Services
Device Types folder named CISCO-ASA-1.2
Step 15
In the Navigation pane, click the CISCO-ASA-1.2 object. The Work pane will display general
information about the Device Package.
Step 16
In the Navigation pane, expand L4-L7 Service Device Types > CISCO-ASA-1.2 > L4-L7
Service Functions > Firewall. The Work pane will display the two types of connectors that
will need to be used to implement a service graph that utilizes the ASAv (you will use these in a
subsequent Task).
Step 17
In the Navigation pane, expand L4-L7 Service Device Types > CISCO-ASA-1.2 > L4-L7
Service Function Profiles > WebPolicyForRoutedMode. The Work pane will display the
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 172
specific properties of the firewall configuration when it is used in routed mode. You will be
using this service function profile in a subsequent Task.
Step 18
Step 19
Step 20
Right-click the Pod##-ASAv VM and then select Power > Power On from the context menu.
Step 21
After a few seconds you should see the powered on icon next to the virtual machine.
Activity Procedure
Complete these steps:
Step 22
Step 23
Step 24
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 25
In the Navigation pane, expand Tenant POD## >Networking > Bridge Domains > POD##BARE-METAL-BD.
Step 26
Step 27
In the Work pane, remove the check mark next to Unicast Routing.
Note
Unchecking the Unicast Routing setting causes the APIC to disable the anycast gateway (SVI)
function for the subnets within the bridge domain.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 173
Step 28
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 29
Step 30
In the Navigation pane, expand Tenant POD## > Application Profiles > POD##APPLICATION-PROFILE > Application EPGs > EPG POD##-DB-EPG.
Step 31
Step 32
Click the SUBMIT button at the bottom of the Work pane. A Policy Usage Warning will
appear indicating the other objects that will be affected by the changes.
Step 33
Activity Procedure
Complete these steps:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 174
Step 34
In the Navigation pane, expand Tenant POD## > L4-L7 Services > Function Profiles.
Step 35
Right-click the Function Profiles folder and then select Create Profile Group from the
context menu.
Step 36
The Create L4-L7 Services Function Profile Group wizard will appear. In the Name field
type POD##-SERVICES-FUNCTION-PROFILE-GROUP (replace ## with your assigned
2-digit Pod Number).
Step 37
Click the SUBMIT button to complete the Create L4-L7 Services Function Profile Group
wizard.
Activity Procedure
Step 38
In the Navigation pane, expand Tenant POD## > L4-L7 Services > Function Profiles >
POD##-SERVICES-FUNCTION-PROFILE-GROUP.
Step 39
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 175
Step 40
The Create L4-L7 Services Function Profile wizard will appear. Enter the values in the
following table.
Field
Value
Name
Checked
Profile
CISCO-ASA-1.2/WebPolicyForRoutedMode
Step 41
The lower portion of the wizard is where you define how the ASAv will behave when it is
deployed. In the next few steps you will configure the IP addresses that will be applied to the
interfaces of the ASAv.
Step 42
In the Features and Parameters section, under Features, make sure that Interfaces is
selected.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 176
Step 43
Under the Basic Parameters tab, expand Device Config > Interface Related Configuration
(externalIf) > Interface Specific Configuration (externalIfCfg) > IPv4 Address
Configuration.
Step 44
Double-click the parameter named IPv4 Address; this will allow you to edit the IP address.
Step 45
In the Value field, type 10.##.4.254/255.255.255.0 (replace ## with your assigned 2-digit
Pod Number).
Step 46
Step 47
Under the Basic Parameters tab, expand Device Config > Interface Related Configuration
(internalIf) > Interface Specific Configuration (internalIfCfg) > IPv4 Address
Configuration.
Step 48
Double-click the parameter named IPv4 Address; this will allow you to edit the IP address.
Step 49
In the Value field, type 10.##.2.254/255.255.255.0 (replace ## with your assigned 2-digit
Pod Number).
Step 50
Step 51
Click the SUBMIT button to complete the Create L4-L7 Services Function Profile wizard.
Note
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 177
PROFILE and re-create it. If there are any faults present and you continue to the next Task the
lab exercise will fail.
Activity Procedure
Complete these steps:
Step 52
In the Navigation pane, expand Tenant POD## > L4-L7 Services > L4-L7 Devices.
Step 53
Right-click the L4-L7 Devices folder and then select Create L4-L7 Devices from the context
menu.
Step 54
The Create L4-L7 Devices wizard will appear. In STEP 1 > General, enter the values in the
following table; do NOT change any of the values that are not listed in the following table.
Field
Value
General Section:
Managed
Checked
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 178
Field
Value
Name
Service Type
Firewall
Device Type
Virtual
VMM Domain
Mode
Single Node
Device Package
CISCO-ASA-1.2
Model
ASAv
Function Type
Go To
Connectivity Section:
APIC to Device Management
Connectivity
Out-Of-Band
Credentials Section:
Username
1234QWer
Device 1:
Management IP Address
Management Port
https
VM
Step 55
In the Devices Interfaces subsection, click the plus sign to create a new entry. Enter the values
in the following table.
Field
Value
Name
GigabitEthernet0/0
vNIC
Network adapter 2
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 179
Step 56
Step 57
In the Devices Interfaces subsection, click the plus sign to create a new entry. Enter the values
in the following table.
Field
Value
Name
GigabitEthernet0/1
vNIC
Network adapter 3
Step 58
Step 59
In the Cluster subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Type
Consumer
Name
Outside
Concrete Interfaces
Device1/GigabitEthernet0/0
Step 60
Step 61
In the Cluster subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 180
Field
Value
Type
Provider
Name
Inside
Concrete Interfaces
Device1/GigabitEthernet0/1
Step 62
Step 63
Click the NEXT button. Do not make any changes in STEP 2 > Device Configuration.
Step 64
Click the FINISH button to complete the Create L4-L7 Devices wizard.
Step 65
In the Navigation pane, expand Tenant POD## > L4-L7 Services > L4-L7 Devices > POD##MANAGED-ASAv. You can see the state of the ASAv virtual machine as seen by the APIC.
Note
The key field in this object is the Configuration State/Configuration Issues/Devices State field. At
this point the Device State should be stable. If the Device state is not stable this means the
APIC cannot communicate with the ASAv virtual machine via the ASAv management interface.
Verify that the ASAv is online and that you can SSH to it. If you can SSH to the ASAv and the
Device State is not stable the quickest path forward is to delete POD##-MANAGED-ASAv and
recreate it following the steps in this Task.
Note
At this point it is likely that you will see faults raised in this object; that is normal (as long as the
Device State is stable). The faults will be cleared once the virtual machine is incorporated into a
service graph.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 181
Note
At this point, nothing has occurred in the ASAv virtual machine, you have just created a device
definition that will be used in a subsequent Task.
Activity Procedure
Complete these steps:
Step 66
In the Navigation pane, expand Tenant POD## > L4-L7 Services > L4-L7 Service Graph
Templates.
Step 67
Right-click the L4-L7 Service Graph Templates folder and then select Create a L4-L7
Service Graph Template from the context menu.
Step 68
The Create a L4-L7 Service Graph Template wizard will appear. In the Graph Name field,
type POD##-SERVICE-GRAPH-TEMPLATE (replace ## with your assigned 2-digit Pod
Number).
Step 69
In the Device Clusters section you should see one entry for the POD##-MANAGED-ASAv
firewall that you created in the previous Task. Drag and drop the firewall into the center of the
window.
Note
The name under the firewall object will be highlighted and have the value N1. Do not change
this value.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 182
Step 70
Field
Value
Firewall
Routed
Profile
Step 71
Click the SUBMIT button to complete the Create a L4-L7 Service Graph Template wizard.
Activity Procedure
Complete these steps:
Step 72
In the Navigation pane, expand Tenant POD## > L4-L7 Services > L4-L7 Service Graph
Templates > POD##-SERVICE-GRAPH-TEMPLATE.
Step 73
Right-click the POD##-SERVICE-GRAPH-TEMPLATE folder and then select Apply L4L7 Service Graph Template from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 183
Step 74
The Apply L4-L7 Service Graph Template To EPGs wizard will appear. In STEP 1 >
Contract, enter the values in the following table.
Field
Value
Consumer EPG /
External Network
POD##/POD##-APPLICATION-PROFILE/epg-POD##-BARE-METAL-EPG (replace
## with your assigned 2-digit Pod Number)
Contract
Step 75
Click the NEXT button. In STEP 2 > Graph, do not make any changes.
Step 76
Click the NEXT button. In STEP 3 > POD##-MANAGED-ASAv Parameters, do not make
any changes.
Step 77
Click the FINISH button to complete the Apply L4-L7 Service Graph Template To EPGs
wizard.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 184
In this task, you will verify that the ASAv firewall has been reconfigured by the APIC, and you will verify
that the service graph is functioning by opening an SSH session from the DB server to the bare metal switch.
Activity Procedure
Complete these steps:
Step 78
From your Student Server desktop, start a PuTTY session with Pod##-ASAv using the
following credentials:
IP Address: 192.168.R0.<##+50>
Step 79
Step 80
Execute the show interface ip brief command. This command will indicate the interfaces
present in the firewall, the state of each interface, and the IP address of each interface. You
should see that the IP address of GigabitEthernet0/0 has been set to 10##.4.254 and the IP
address of GigabitEthernet0/1 has been set to 10##.2.254 (the Management0/0 interface is the
out-of-band management interface and is part of the lab baseline).
ip brief
IP-Address
10.11.4.254
10.11.2.254
unassigned
unassigned
unassigned
unassigned
unassigned
unassigned
unassigned
192.168.30.61
YES
YES
YES
YES
YES
YES
YES
YES
YES
YES
manual
manual
unset
unset
unset
unset
unset
unset
unset
manual
up
up
administratively
administratively
administratively
administratively
administratively
administratively
administratively
up
down
down
down
down
down
down
down
up
up
up
up
up
up
up
up
up
up
Step 81
Execute the show nameif command. This command will show you the security levels assigned
to the interfaces within the firewall.
Note
The Cisco ASA series of firewalls uses the concept of a security level to help determine traffic
flows from one interface to another. By default, traffic is allowed to flow from an interface with a
higher security level to an interface with a lower security level. In order to allow traffic to flow
from an interface with a lower security level to an interface with a higher security level an access
list must be configured to allow the traffic.
Name
externalIf
internalIf
management
Security
50
100
0
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 185
Step 82
Execute the ping 10.##.2.1 command. This command will verify that the inside interface of the
firewall can communicate with the DB server.
Step 83
Execute the ping 10.##.4.1 command. This command will verify that the outside interface of
the firewall can communicate with the DB server.
Step 84
Execute the show arp command. This command will list all of the IP address to MAC address
mappings present in the firewalls memory.
Step 85
Step 86
Step 87
Navigate to vCenter-@ > Datastore-@ > Cluster-@ (replace @ with your assigned vCenter
letter).
Step 88
At the bottom of the window is the Recent Tasks pane. You should see three entries there:
One entry indicating that the POD##-VMM-DOMAIN DVS has been modified and now has two
additional port groups created by the APIC
Two entries indicating that the Pod##-ASAv virtual machine has been modified to use these two
new port groups
Step 89
Right-click the Pod##-ASAv VM and then select Edit Settings from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 186
Step 90
The Virtual Machine Properties window will appear. You should see that network adapters 2
and 3 have been reconfigured to use port groups in the Pod VMM Domains distributed virtual
switch.
Step 91
Click the Cancel button to close the Virtual Machine Properties window.
Step 92
Right-click the Pod##-DB VM and then select Open Console from the context menu.
Step 93
The console window for Pod##-DB will appear. You will see the DB servers desktop.
Step 94
Note
At this point the configuration of the service graph is complete. Next, you will use PuTTY to verify
that you can open a TCP/IP session from the DB Server, which is inside the firewall, to the
bare metal server, which is outside the firewall.
Step 95
Step 96
Open an SSH session to the bare metal server using the following information:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 187
Step 97
If you are able to start an SSH session that indicates the service graph is functioning properly.
Note
Actually, there is no bare metal server, a virtual router has been configured to duplicate the
network connectivity of a bare metal server.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 188
Configure local users and roles for your tenant security domain
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
Step 7
Step 8
Step 9
Right-click the Security Domains folder and then select Create Security Domain from the
context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 189
Step 10
The Create Security Domain wizard will appear. In the Name field type POD##-SD-LOCAL
(replace ## with your assigned 2-digit Pod Number).
Step 11
Click the SUBMIT button to complete the Create Security Domain wizard.
Step 12
Step 13
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 14
In the Navigation pane, click Tenant POD##, and then click the POLICY tab in the Work
pane.
Step 15
Step 16
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 190
Task 2: Configure Local Users and Roles for your Tenant Security
Domain
In this task, you will create tenant-specific admin and audit users with the appropriate roles and map them to
your tenant security domain.
Activity Procedure
Complete these steps:
Step 17
Step 18
Step 19
Step 20
Right-click the Local Users folder and then select Create Local User from the context menu.
Step 21
The Create Local User wizard will appear. In STEP 1 > Security, in the Security Domain
subsection, click the checkbox next to POD##-SD-LOCAL.
Step 22
Click the NEXT button. In STEP 2 > Roles, select READ WRITE for each of the roles listed.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 191
Step 23
Click the NEXT button. In STEP 3 > User Identity, enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Login ID
1234QWer
Step 24
Click the FINISH button to complete the Create Local User wizard.
Step 25
Right-click the Local Users folder and then select Create Local User from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 192
Step 26
The Create Local User wizard will appear. In STEP 1 > Security, in the Security Domain
subsection, click the checkbox next to POD##-SD-LOCAL.
Step 27
Click the NEXT button. In STEP 2 > Roles, select READ ONLY for each of the roles listed.
Step 28
Click the NEXT button. In STEP 3 > User Identity, enter the values in the following table; do
NOT change any of the values that are not listed in the following table.
Field
Value
Login ID
1234QWer
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 193
Step 29
Click the FINISH button to complete the Create Local User wizard.
Activity Procedure
Complete these steps:
Step 30
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
admin, and then select Logout from the drop-down menu.
Step 31
Mode: Advanced
Step 32
The first screen that you will see is the Dashboard. Notice how there is nothing visible; the
POD##-ADMIN-LOCAL account does not have system-wide rights. Also notice how many of
the Menu bar selections are greyed out.
Step 33
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 194
Step 34
In the Submenu bar, click ALL TENANTS. Notice how there are only two Tenants listed,
common and POD##.
Step 35
Step 36
Navigate to various portions of your Tenant. Notice how you have the ability to change the
configuration of your Tenant.
Step 37
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
POD##-ADMIN-LOCAL, and then select AAA > View My Permissions from the drop-down
menu.
Step 38
The User Permissions window will appear. This window will display all of the permissions
that have been granted to the user account with which you are currently logged in.
Step 39
Step 40
Step 41
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 195
Mode: Advanced
Step 42
The first screen that you will see is the Dashboard. Notice how there is nothing visible; the
POD##-AUDIT-LOCAL account does not have system-wide rights. Also notice how many of
the Menu bar selections are greyed out.
Step 43
Step 44
In the Submenu bar, click ALL TENANTS. Notice how there are only two Tenants listed,
common and POD##.
Step 45
Step 46
Navigate to various portions of your Tenant. Notice how you have the ability to view the
configuration of your Tenant, however you cannot make any changes to the configuration.
Step 47
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
POD##-AUDIT-LOCAL, and then select AAA > View My Permissions from the drop-down
menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 196
Step 48
The User Permissions window will appear. This window will display all of the permissions
that have been granted to the user account with which you are currently logged in.
Step 49
Step 50
Activity Procedure
Complete these steps:
Step 51
Step 52
Step 53
Step 54
Step 55
Right-click the RADIUS Provider Groups folder and then select Create RADIUS Provider
Group from the context menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 197
Step 56
The Create RADIUS Provider Group wizard will appear. In the Name field, type
POD##_RADIUS_PROVIDER_GROUP (replace ## with your assigned 2-digit Pod
Number).
Note
The name of the RADIUS Provider Group may not use the dash character; however you may
use the underscore character.
Step 57
In the Providers subsection, click the plus sign to create a new entry. Enter the values in the
following table.
Field
Value
Name
Priority
Step 58
Step 59
Click the SUBMIT button to complete the Create RADIUS Provider Group wizard.
Step 60
Step 61
Right-click the Login Domains folder and then select Create Login Domain from the context
menu.
Step 62
The Create Login Domain wizard will appear. Enter the values in the following table.
Field
Value
Name
Realm
RADIUS
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 198
Field
Value
Note
The name of the Login Domain may not use the dash character; however you may use the
underscore character.
Step 63
Click the SUBMIT button to complete the Create Login Domain wizard.
Step 64
Step 65
Right-click the Security Domains folder and then select Create Security Domain from the
context menu.
Step 66
The Create Security Domain wizard will appear. In the Name field type POD##-SDRADIUS (replace ## with your assigned 2-digit Pod Number).
Note
It is important that you enter this value correctly because it is a value that is used by the RADIUS
server to assign av pairs to the login account.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 199
Step 67
Click the SUBMIT button to complete the Create Security Domain wizard.
Step 68
Step 69
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 70
In the Navigation pane, click Tenant POD##, and then click the POLICY tab in the Work
pane.
Step 71
Step 72
Activity Procedure
Complete these steps:
Step 73
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
admin, and then select Logout from the drop-down menu.
Step 74
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 200
Mode: Advanced
Step 75
The first screen that you will see is the DASHBOARD. Notice how there is nothing visible; the
POD##-ADMIN-RAD account does not have system-wide rights. Also notice how many of the
Menu bar selections are greyed out.
Step 76
Step 77
In the Submenu bar, click ALL TENANTS. Notice how there is only one Tenant listed,
POD##.
Step 78
Step 79
Navigate to various portions of your Tenant. Notice how you have the ability to change the
configuration of your Tenant.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 201
Step 80
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
POD##-ADMIN-RAD, and then select AAA > View My Permissions from the drop-down
menu.
Step 81
The User Permissions window will appear. This window will display all of the permissions
that have been granted to the user account with which you are currently logged in.
Step 82
Step 83
Step 84
Mode: Advanced
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 202
Step 85
The first screen that you will see is the Dashboard. Notice how there is nothing visible; the
POD##-AUDIT-LOCAL account does not have system-wide rights. Also notice how many of
the Menu bar selections are greyed out.
Step 86
Step 87
In the Submenu bar, click ALL TENANTS. Notice how there is only one Tenant listed,
POD##.
Step 88
Step 89
Navigate to various portions of your Tenant. Notice how you have the ability to view the
configuration of your Tenant, however you cannot make any changes to the configuration.
Step 90
In the upper right-hand corner of the APIC GUI, click the down arrow to the right of welcome,
POD##-AUDIT-RAD, and then select AAA > View My Permissions from the drop-down
menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 203
Step 91
The User Permissions window will appear. This window will display all of the permissions
that have been granted to the user account with which you are currently logged in.
Step 92
Step 93
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 204
Activity Procedure
Complete these steps:
Step 1
Step 2
Step 3
Step 4
Username: admin
Step 5
Activity Procedure
Complete these steps:
Step 6
To view a summary of fault statistics for the overall system, click SYSTEM from the main
menu.
Step 7
In the Dashboard, the dashboard tables display the fault counts by domain and by type.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 205
Note
Step 8
Next, you will view the faults that are related to a Tenant. In the Menu bar, click Tenants.
Step 9
In the Submenu bar, click POD## (replace ## with your assigned 2-digit Pod Number).
Step 10
In the Navigation pane, select Tenant POD##. The Work pane will display a Dashboard
specific to the Tenant.
Step 11
In the Work pane, click the FAULTS tab. Take a moment to review any recorded faults.
Note
If you have performed all of the previous lab exercises properly there should not be any faults
listed
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 206
Step 12
By clicking specific ACI constructs (e.g. Application Profiles, Bridge Domains, etc.), in the
Navigation pane, you will have access to the Faults tab which records all faults that are specific
to the current GUI context.
Step 13
Step 14
Step 15
Step 16
In the Work pane, retention policy settings appear for the following logs:
Note
The Controller Policies folder is the location where you manage the sizes of the different
controller policies. These policies are for issues that are specific to the controller.
Note
The maximum size range is 1,000 to 500,000 records; the default is 100,000 records. The Purge
Window Size is the maximum number of records to be deleted in a single swipe once the
number of records in the log is greater than the Maximum Size. The Purge Window Size default
is designed to minimize impact on performance when records are purged.
Step 17
In the Navigation pane, expand Switch Policies. This is the location where you can manage the
size of the various switch log retention policies.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 207
Many places in the GU present the logged events. The events are filtered to show only those events that are
relevant to the current GUI context. Wherever a History tab appears in the GUI work pane, you can view the
relevant log entries from the event log, health log, or audit log.
Activity Procedure
Complete these steps:
Step 18
In the Menu bar, click Admin, and then in the Submenu bar, click AAA.
Step 19
Step 20
Step 21
Step 22
Under the HISTORY tab, click the AUDIT LOG subtab to view the audit log.
Step 23
Double-click a log entry to view more details about the event if an entry exists.
Step 24
Activity Procedure
Complete these steps:
Step 25
In the upper right corner of the APIC window, click the welcome, admin message to view the
drop-down menu.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 208
Step 26
In the drop-down menu, choose the Show API Inspector. The API Inspector opens in a new
browser window.
Step 27
Arrange the APIC browser window side-by-side with the API Inspector window, and then click
the Newest at the top check box.
Note
This action allows you to interact with the APIC GUI and simultaneously observe the API calls
that are made in reaction to your interactions with the GUI.
Step 28
In the Filters toolbar of the API Inspector window, choose the types of API log messages to
display.
The displayed messages are color-coded according to the selected message types. This table shows the
available message types:
Log
Type
Description
debug
Displays debug messages. This type includes most API commands and responses.
info
warn
error
fatal
all
Checking this check box causes all other check boxes to become checked. Unchecking any other check
box causes this check box to be unchecked.
Step 29
In the APIC GUI, click Tenants from the Menu bar, and then click the common Tenant.
Step 30
In the Navigation pane, right-click Application Profiles, and then choose Create Application
Profile from the context menu.
Step 31
Step 32
In the API Inspector, observe that there is a POST method request that instructs the API to
create a new application profile in the Common Tenant. That the request will be in the JSON
format. The JSON format is not obvious in the API Inspector window. The following is an
example of the request:
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 209
"name":"ATL-TEMP","rn":"ap-ATL-TEMP","status":"created"},"children":[]}}
response: {"imdata":[]}
Step 33
Open the Notepad++ application on your desktop. Copy and paste the payload into a new
document.
Step 34
Press and hold down the Ctrl key followed by the A key to select all.
Step 35
Step 36
Click JSON Viewer, and then Format JSON. Your output should now appear in JSON array
format.
You can use the URL and JSON array that are recovered from the API Inspector to make REST calls to
configure the fabric.
Only the Firefox, Chrome, and Safari browsers are supported for Visore access.
Activity Procedure
Complete these steps:
Step 37
Step 38
Step 39
Username: admin
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 210
Step 40
The APIC Object Store Browser will appear. In the Class or DN field, type
aaaProviderGroup, and then click the Run Query button.
Note
If a window pops up saying You did not specify a property name, click OK.
Step 41
The query results show a number of AAA Provider Groups that are named
aaaRadiusProviderGroup with the format POD##_RADIUS_PROVIDER_GROUP. These
are the RADIUS Provider Groups that were created in the previous lab exercise.
Step 42
Click the green > symbol at the end of the dn field. This action will take you to the details of
that DN, if it exists in the object tree.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 211
Note
Clicking > sends a query to the APIC for the children of the MO (managed object).
Clicking < sends a query for the parent of the MO.
Step 43
In the dn field of the MO description table, click the icons to display statistics, faults, or health
information for the MO.
Step 44
Click the Display URI of last query link to display the API call that executed the query.
Step 45
Click the Display last response link to display the API response data structure from the query.
Activity Procedure
Complete these steps:
Step 46
On your Student Server desktop, start the 3CDaemon application. You will be using this later in
this lab exercise.
Step 47
Step 48
Step 49
Step 50
Step 51
Right-click the Syslog folder and then select Create Syslog Monitoring Destination Group
from the context menu
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 212
Step 52
The Create Syslog Monitoring Destination Group wizard will appear. In STEP 1 > Profile,
in the Name field type POD##-SYSLOG-GROUP (replace ## with your assigned 2-digit
Pod Number).
Step 53
Click the NEXT button. In STEP 2 > Remote Destinations, in the Create Remote
Destinations subsection, click the plus sign to create a new entry.
Step 54
The Create Syslog Remote Destination wizard will appear. Enter the values in the following
table.
Field
Value
IP Address To NterOne Lab (this can be found on your Student Server desktop in
the upper right-hand corner)
Host
Name
Admin State
Enabled
Management EPG
default (Out-of-Band)
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 213
Step 55
Click the OK button to complete the Create Syslog Remote Destination wizard.
Step 56
Click the FINISH button to complete the Create Syslog Monitoring Destination Group wizard.
Note
In the previous steps, you configured the syslog server. In the next steps, you will configure a
syslog policy that will result in the generation of syslog messages to the syslog server.
Step 57
Step 58
Step 59
In the Navigation pane, expand Monitoring Policies > default > CallHome/SNMP/Syslog.
Note
You can also access Monitoring Policies under individual tenants and Fabric Access Policies.
Step 60
Step 61
In the far right-hand side of the Work pane click the plus sign to create a new entry.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 214
Step 62
The Create Syslog Source wizard will appear. Enter the values in the following table.
Field
Value
Name
Min Severity
debugging
Include
Dest. Group
Step 63
Step 64
Step 65
Click the Syslog Server tab to display syslog messages from the APIC.
Note
Activity Procedure
Complete these steps:
Step 66
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 215
Step 67
Step 68
Step 69
In the Session Name field type POD##-SESSION (replace ## with your assigned 2-digit
Pod Number).
Step 70
In the Source field, enter 10.##.1.1 (the IP address of Pod##-App) and then click the Search
button.
Step 71
You should see a single search result. Click it, which will cause the row to turn grey.
Step 72
In the Destination field, enter 10.##.3.1 (the IP address of Pod##-Web) and then click the
Search button.
Step 73
You should see a single search result. Click it, which will cause the row to turn grey.
Step 74
Step 75
After a few seconds, the Faults screen appears. Observe any possible faults on the system.
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 216
Step 76
Click Drops/Stats in the Navigation Pane. Observe that there have been some drops in the
system due to you changing the configuration of the fabric.
Step 77
Click Contracts in the Navigation Pane. You should see packets from pinging between the
virtual machines from the previous lab exercises.
Step 78
Click Traceroute in the Navigation Pane. From the Protocol drop-down menu, choose icmp.
Press the Play button in the top left part of the window.
Step 79
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 217
Step 80
After a few seconds, the interface will display the result of a traceroute. Observe that the
Traceroute Status is complete and that the arrows in the screen are green.
Step 81
Configuring Cisco Nexus 9000 Series Switches in ACI Mode (DCAC9K) Lab Guide v1.2 rev A
2016 NterOne Corporation
Page 218