procedures for creating interface and switch policies and ... · procedures for creating interface...

12
Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Using the unified configuration wizard is the recommended method for performing configuration tasks before you install the Cisco AVS. However, you might need to configure separate, more detailed policies. This appendix includes individual procedures for creating different kinds of interface and switch policies and for creating a vCenter profile. Creating Port Channel Switch and Interface Profiles, page 1 Creating VPC Switch and Interface Profiles, page 3 Creating FEX Node Switch and Interface Profiles, page 5 Modifying the Interface Policy Group to Override the vSwitch-Side Policies, page 6 Creating a VMware vCenter Domain Profile, page 8 Creating Port Channel Switch and Interface Profiles If you choose MAC pinning link-aggregation while creating a port channel node policy and, in the section Creating a VMware vCenter Domain Profile, on page 8, you choose VXLAN encapsulation, we recommend that you enable VXLAN load-balancing. See the section Enabling VXLAN load-balancingin the Cisco Application Virtual Switch Configuration Guide. Note Step 1 Log in to the Cisco APIC, choosing Advanced mode. Step 2 Choose Fabric > Access Policies. Step 3 In the Policies navigation pane, open the Switch Policies folder, right-click the Profiles folder, and then choose Create Switch Profile. Step 4 In the Create Switch Profile STEP 1 > Profile dialog box, complete the following steps: a) In the Name field, enter a name. (avsSwitchProfile) b) In the Switch Selectors field, click the + icon to create a new switch selector. Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 1

Upload: others

Post on 06-Aug-2020

3 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Procedures for Creating Interface and SwitchPolicies and Creating a vCenter Domain Profile

Using the unified configuration wizard is the recommendedmethod for performing configuration tasks beforeyou install the Cisco AVS. However, you might need to configure separate, more detailed policies.

This appendix includes individual procedures for creating different kinds of interface and switch policiesand for creating a vCenter profile.

• Creating Port Channel Switch and Interface Profiles, page 1

• Creating VPC Switch and Interface Profiles, page 3

• Creating FEX Node Switch and Interface Profiles, page 5

• Modifying the Interface Policy Group to Override the vSwitch-Side Policies, page 6

• Creating a VMware vCenter Domain Profile, page 8

Creating Port Channel Switch and Interface Profiles

If you choose MAC pinning link-aggregation while creating a port channel node policy and, in the sectionCreating a VMware vCenter Domain Profile, on page 8, you choose VXLAN encapsulation, werecommend that you enable VXLAN load-balancing. See the section “Enabling VXLAN load-balancing”in the Cisco Application Virtual Switch Configuration Guide.

Note

Step 1 Log in to the Cisco APIC, choosing Advanced mode.Step 2 Choose Fabric > Access Policies.Step 3 In the Policies navigation pane, open the Switch Policies folder, right-click the Profiles folder, and then choose Create

Switch Profile.Step 4 In the Create Switch Profile STEP 1 > Profile dialog box, complete the following steps:

a) In the Name field, enter a name. (avsSwitchProfile)b) In the Switch Selectors field, click the + icon to create a new switch selector.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 1

Page 2: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

c) In the Name field, enter a name. (node101)d) In the Blocks field, choose a leaf switch node ID from the drop-down list. (101)

This node ID must match the node ID of the leaf switch that is connected to the ESXi or Layer 2 cloud host.You can confirm this value in the Fabric Membership window.

Note

e) Click UPDATE.f) Click NEXT.

Step 5 In the Create Switch Profile STEP 2 > Associations dialog box, in the Interface Selectors Profiles area, click the +icon to create a new interface selector profile.

Step 6 In the Create Interface Profile dialog box, complete the following steps:a) In the Name field, enter the vLeaf name. (node101-vleaf1)b) In the Interface Selectors area, click the + icon to create a new interface selector.

Step 7 In the Create Access Port Selector dialog box, complete the following steps:a) Enter a name for the selector in the Name field. (node101vLeaf1)b) In the Interface IDs field, enter the access port interface IDs for the physical interfaces connected to the ESXi host.

(1/19–1/20)c) In the Interface Policy Group drop-down list, choose Create PC Interface Policy.

Step 8 In the Create PC Interface Policy Group dialog box, enter the policy group name in the Name field. (PCBundle)Step 9 In the Port Channel Policy field, choose Create Port Channel Policy from the drop-down list.Step 10 In the Create Port Channel Policy dialog box, complete one of the following steps:

a) Enter the policy name in the Name field. (PCBundle1)b) In theMode field, choose one of the following values:

• Static Channel - Mode On

• LACP Active

• LACP Passive

•MAC Pinning

c) Click SUBMIT.

Step 11 In the Create PC Interface Policy Group dialog box, complete the following steps:a) In the Attached Entity Profile field, default from the drop-down list.

You can create a new attachable access entity profile to override policy after you create the node policy. You mightneed to do so if you have intermediate Layer 2 devices between the leaf and ESXi hosts that are running the CiscoAVS and if you want to use LACP with the top of rack (TOR) switch/leafs on the fabric side but use another policy,such as Mac Pinning, on the Cisco AVS side.

See the sections "About Attachable Entity Profiles" and "Creating an Attachable Entity Profile to Override LinkAggregation Policy on the Cisco AVS."

b) Click SUBMIT.

Step 12 In the Create Access Port Selector dialog box, click OK.Step 13 In the Create Interface Profile dialog box, click SUBMIT.Step 14 In the Create Switch Profile dialog box, choose the new interface profile and then click FINISH.

The new switch profile (avsSwitchProfile) displays in the Switch Policies - Profiles area.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)2

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating Port Channel Switch and Interface Profiles

Page 3: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Creating VPC Switch and Interface Profiles

If you chooseMAC pinning link-aggregation while creating a VPC node policy and, in the section Creatinga VMware vCenter Domain Profile, on page 8, you choose VXLAN encapsulation, we recommend thatyou enable VXLAN load-balancing. See the section “Enabling VXLAN load-balancing” in theCiscoApplication Virtual Switch Configuration Guide.

Note

Step 1 Log in to the Cisco APIC, choosing Advanced mode, and then, choose Fabric > Access Policies.Step 2 In the Policies navigation pane, open the Switch Policies folder.Step 3 Open the Policies folder.Step 4 You can use the Virtual Port Channel default domain or create a new domain. To create a new domain, right-click

VPC Domain and choose Create VPC Domain Policy.Step 5 In the Create VPC Domain Policy dialog box, complete the following steps:

a) In the Name field, enter a name for the policy.b) In the Peer Dead Interval field, enter a value.c) Click SUBMIT to save the policy.

Step 6 In the Policies navigation pane, under the Switch Policies folder, right-click Profiles and chooseCreate Switch Profile.Step 7 In the Create Switch Profile dialog box, complete the following steps:

a) In the Name field, enter a profile name. (avsSwitchProfile)b) In the Switch Selectors area, click the + icon.c) In the Name field, enter a name. (node101).d) In the Blocks drop-down list, choose a leaf.e) Click on the drop-down arrow in the Blocks field or anywhere on the Create Switch Profile dialog box so you can

see the UPDATE button.f) Click UPDATE.g) Click NEXT.

Step 8 In the Create Switch Profile dialog box, in the click Interface Selector Profiles area, click the + icon.Step 9 In the Create Interface Profile dialog box, complete the following steps:

a) In the Name field, enter a profile name. (node101-vLeaf)b) In the Interface Selectors area, click the + icon.

Step 10 In the Create Access Port Selector dialog box, complete the following actions:a) In the Name field, enter a selector name. (node101vLeaf1)b) In the Interface IDs field, enter a range value. It should be the port on the leaf. (1/31, 1/33, etc.)c) In the Interface Policy Group field, choose Create VPC Interface Policy Group from the drop-down list.

Step 11 In the Create VPC Interface Policy Group dialog box, complete the following steps:a) In the Name field, enter a policy group name. (vpc)b) In the Port Channel Policy field, choose Create Port Channel Policy from the drop-down list.

Step 12 In the Create Port Channel Policy dialog box, complete the following actions:

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 3

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating VPC Switch and Interface Profiles

Page 4: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

a) In the Name field, enter a policy name. (pc-policy1)b) In theMode field, choose one of the following options appropriate to your setup:

• Static Channel - Mode On

• LACP Active

• LACP Passive

•MAC Pinning

c) Click SUBMIT.

Step 13 In the Create VPC Interface Policy Group dialog box, complete the following actions:a) In the Attached Entity Profile field, choose default from the drop-down list.

You can create a new attachable entity profile to override policy after you create the node policy. You might needto do so if you have intermediate Layer 2 devices between the leaf and ESXi hosts that are running the Cisco AVSand if you want to use LACP with the top of rack (TOR) switch/leafs on the fabric side but use another policy, suchas Mac Pinning, on the Cisco AVS side.

See the sections "About Attachable Entity Profiles" and "Creating an Attachable Entity Profile to Override LinkAggregation Policy on the Cisco AVS."

b) Click SUBMIT.

Step 14 In the Create Access Port Selector dialog box, click OK.Step 15 In the Create Interface Profile dialog box, click SUBMIT.Step 16 In the Create Switch Profile dialog box, complete the following steps:

a) In the Interface Selector Profiles area, check the check box for the interface selector profile that you created in Step9 a.

b) Click FINISH.

Step 17 To add a second leaf to the VPC, complete the following steps:a) Repeat Step 1 through Step 10 b; however at Step 7 b, enter the node ID of the other leaf. (node102)b) In the Create Access Port Selector dialog box, choose the name of the policy group that you created in Step 11 a.

(vpc)c) Click OK.d) Repeat Step 15 and Step 16.

Step 18 In the Policies navigation pane, expand the Switch Policies folder and then the Policies folder, right-click Virtual PortChannel default, and then choose Create VPC Explicit Protection Group.

Step 19 In theCreate VPC Explicit Protection Group dialog box, enter a name, ID, and switch values for the protection group.Click SUBMIT to save the protection group.

Each pair of leaf switches has one VPC Explicit Protection Group with a uniqueID.

Note

The same virtual port channel policy can contain multiple VPC explicit protection groups.Note

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)4

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating VPC Switch and Interface Profiles

Page 5: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Creating FEX Node Switch and Interface Profiles

If you have a FEX directly connected to a leaf, see the section Cisco Fabric Extender, for informationabout limitations.

Note

Step 1 Log in to the Cisco APIC GUI, choosing Advanced mode, and then choose Fabric > Access Policies.Step 2 In the Policies navigation pane, open the Switch Policies folder, right-click the Profiles folder, and then choose Create

Switch Profile.Step 3 In the Create Switch Profile STEP 1 > Profile dialog box, complete the following steps:

a) In the Name field, enter a profile name. (fex1-CEP)b) In the Switch Selectors field, click the + icon.c) In the Name field, enter a name. (node101)d) In the Blocks field, choose a leaf switch node ID that is connected with the FEX from the drop-down list.

This node ID must match the node ID of the leaf switch that is connected to the ESXi or Layer 2 cloud host.You can confirm this value in the Fabric Membership window.

Note

e) Click on the Blocks drop-down arrow or anywhere on the Create Switch Profile dialog box so you can see theUPDATE button.

f) Click UPDATE.g) Click NEXT.

Step 4 In the Create Switch Profile STEP 2 > Associations dialog box, in the Interface Selectors Profiles area, click the +icon to create a new interface selector profile.

Step 5 In the Create Interface Profile dialog box, complete the following steps:a) In the Name field, enter the vLeaf name. (node101-vleaf1)b) In the Interface Selectors area, click the + icon to create a new interface selector.

Step 6 In the Create Access Port Selector dialog box, complete the following steps:a) Enter a name for the selector in the Name field (node101vLeaf1).b) In the Interface IDs field, enter the access port interface IDs on the leaf that is connected to the FEX.c) Check the Connected To Fex check box.d) From the FEX Profile drop-down list, choose Create FEX profile.

Step 7 In the Create FEX Profile dialog box, complete the following steps:a) In the Name field, enter an FEX profile name.b) In the FEX Access Interface Selectors area, click the + icon to specify the FEX access ports.

Step 8 In the Create Access Port Selector dialog box, complete the following steps:a) In the Name field, enter a selector name.b) In the Interface IDs area, specify the access ports on the FEX that are connected to the ESXi server hosting the Cisco

AVS.c) In the Interface Policy Group area, choose an option from the drop-down list.

You can choose Create PC Interface Policy Group, Create VPC Interface Policy Group, or Create Access PortPolicy Group.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 5

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating FEX Node Switch and Interface Profiles

Page 6: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Step 9 In the dialog box for the option that you chose in Step 8c, complete the following steps:a) In the Name field, enter an access policy group name.b) In the Attached Entity Profile area, choose the appropriate attached entity profile.c) Click SUBMIT.

Step 10 In the Create Access Port Selector dialog box, verify that the newly created access port policy group appears in theInterface Policy Group area, and then click OK.

Step 11 In the Create FEX Profile dialog box, verify that the newly created FEX access interface selector profile appears in theFEXAccess Interface Selectors area, and then click SUBMIT

Step 12 In the Create Access Port Selector dialog box, complete the following steps:a) Verify that the newly created FEX profile appears in the FEX Profile area.b) Enter an ID in the FEX ID field.c) Click OK.

Step 13 In the Create Interface Profile dialog box, verify that the leaf-side interface port selector profile is present, and thenclick SUBMIT.

Step 14 In the Create Switch Profile STEP 2 > Associations dialog box, in the Interface Selector Profiles area, check thecheck box for the interface selector profile that you created for the FEX, and then click FINISH.

What to Do Next

You should verify that the FEX node policy configuration was successful. However, you need to wait about10 minutes to give the Cisco APIC time to complete the configuration.

To verify the FEX node policy configuration, complete the following steps in the Cisco APIC GUI:

1 Choose FABRIC > INVENTORY.

2 In the Inventory navigation pane, expand the folder for the pod containing the leaf node for which theFEX node profile was created.

3 Expand the folder for the leaf node.

4 Choose the Fabric Extenders folder.

5 In the Fabric Extenders work pane, ensure that the FEX is present.

Modifying the Interface Policy Group to Override thevSwitch-Side Policies

After you create a node policy, you might need to create your own attachable entity profile. This might benecessary if you have intermediate Layer 2 devices—such as the Cisco Nexus 5000/7000 series switches orblade servers (Unified Computing System [UCS])—between the leaf and ESXi hosts that are running theAVS.

The override allows a separate link policy to be configured for the intermediate devices and for the CiscoAVS host uplinks. For example, if you have UCS Fabric Interconnects connected to ACI, and your CiscoAVS hosts are running on UCS blades, you may want the UCS Fabric Interconnect uplinks for each FI

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)6

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileModifying the Interface Policy Group to Override the vSwitch-Side Policies

Page 7: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

channeled using Port Channel policy, but the host vNICs for the UCS blades will be configured separatelyusing MAC Pinning.

Before You Begin

• Before you create a custom attachable entity profile, you must create a VMware vCenter domain. Seethe section Creating a VMware vCenter Domain Profile, on page 8 for more information.

When you create a vCenter domain, you must select an attachable entity profile, butbecause you do not have one yet, leave the Attachable Entity Profile field blank, orchoose default. After you create the custom profile, you can associate it with the vCenter.

Note

• You must ensure that under FABRIC > Access Policies > Interface Policies > Profiles, the desiredinterface profiles with port selectors have been created; you will associate the ports with the overridepolices later.

Step 1 Log in to the Cisco APIC, choosing Advanced mode, and then choose Fabric > Access Policies.Step 2 In the Policies navigation pane, chooseGlobal Policies >Attachable Access Entity Profiles and then right-clickCreate

Attachable Access Entity Profile.Step 3 In the Create Attachable Access Entity Profile, Step 1 > Profiles dialog box, complete the following actions:

a) In the Name field, enter a name for the profile.b) Check the Enable Infrastructure VLAN check box.c) Click the + icon to expand Domains, and add the VMM domain to be associated with the attachable entity profile.d) Click UPDATE.e) Click NEXT.

Step 4 In the Create Attachable Access Entity Profile, Step 2> Association to Interfaces dialog box, choose the interfacepolicy groups that you want to associate with the attachable entity profile.

For each interface policy group, you can choose either theAll or the Specific radio button. TheAll radio buttonassociates all the interfaces from that interface policy group with the attachable entity profile; the Specific radiobutton associates specific interfaces from a specific node. If you choose a Specific radio button for an interfacepolicy group, you will be asked to specify the switch IDs and Interfaces and then click an UPDATE button.

Note

Step 5 In the Create Attachable Access Entity Profile, Step 2> Association to Interfaces dialog box, select the appropriatevSwitch policies, if necessary.

You might need to choose a vSwitch policy if both of the following are true:Note

• The ESXi servers hosting vSwitches are connected to the leaf through a Layer 2 switch or blade server.

• The network requires that the interface group policies—Port Channel, Cisco Discovery Protocol (CDP),Link Layer Discovery Protocol (LLDP), Spanning Tree Protocol (STP), or Firewall—between the Layer2 device and the vSwitch hosted by the ESXi server be different from the interface group policies betweenthe Layer 2 switch and leafs.

You can choose either the Inherit or the Specify radio button. The Inherit option makes the vSwitch policiesthe same as the upstream policies. The Specify option enables you to select separate Port Channel, CDP, LLDP,STP, or Firewall policies for the attachable entity profile.

Note

Step 6 Click FINISH.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 7

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileModifying the Interface Policy Group to Override the vSwitch-Side Policies

Page 8: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Creating a VMware vCenter Domain ProfileUse the following procedure to create a VMware vCenter domain profile. You must create a new VMMdomain profile; you cannot convert an existing one. For information about deleting an existing VMwarevCenter domain profile, see the section "Guidelines for Deleting VMMDomains" inCisco Application CentricInfrastructure Fundamentals.

You can create multiple data centers and DVS entries under a single domain. However, you can have onlyone Cisco AVS assigned to each data center.

Note

If you choose VXLAN encapsulation in this section and MAC pinning link-aggregation in the sectionCreating Port Channel Switch and Interface Profiles, on page 1 or the section Creating VPC Switch andInterface Profiles, on page 3, we recommend that you enable VXLAN load-balancing. See the section“Enabling VXLAN load-balancing” in the Cisco Application Virtual Switch Configuration Guide.

Note

Starting with Cisco AVS Release 5.2(1)SV3(1.10), you can configure vSwitch override policies througha VMM domain. The vSwitch override policies configured on a VMM domain take precedence overvSwitch override policies configured over an Attachable Entity Profile (AEP) attached to that VMMdomain. Configuring vSwitch override policies over a VMM domain enables you to deploy these policiesacross all the hosts that belong to this VMM domain.

Note

Before You Begin

Make sure that the multicast IP address pool has enough multicast IP addresses to accommodate the numberof EPGs created for VXLAN LS and VXLAN NS modes. You can add more IP addresses to a multicastaddress pool that is already associated with a VMware vCenter domain at any time. However, you should notcreate more than 62,000 IP addresses in the multicast pool.

If you want to change the switch mode on a Cisco AVS, you first must remove the existing DVS and thenadd the VMware vCenter domain with the desired switching mode. For instructions on removing the existingDVS, see Cisco Application Virtual Switch Configuration Guide.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)8

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating a VMware vCenter Domain Profile

Page 9: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

If you prefer not to use the vCenter administrator/root credentials, you can create a custom user account.To configure vCenter from Cisco APIC, your credentials must allow the following minimum set ofprivileges within vCenter:

Note

• Alarms

• Data center

• Folder

• Distributed Switch

• dvPortgroup

• Network

• VM

• Host

Step 1 Log in to the Cisco APIC, choosing Advanced mode, and then choose VM Networking > Inventory.Step 2 In the Inventory navigation pane, right-click VMware and choose Create vCenter Domain.Step 3 In the Create vCenter Domain dialog box, complete the following actions:

a) In the Virtual Switch Name field, enter a name. It can be any name that you choose.b) In the Virtual Switch area, choose Cisco AVS.c) In the Switching Preference area, choose No Local Switching or Local Switching.

No Local Switching mode was formerly known as Fex Enable mode; Local Switching mode was formerlyknown as Fex Disable mode.

Note

Step 4 Complete one of the following series of steps, depending on whether you chose No Local Switching or Local Switchingas your switching preference in Step 3c.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 9

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating a VMware vCenter Domain Profile

Page 10: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Then...If your switchingpreference is...

In the Create vCenter Domain dialog box, complete the following actions:

1 From the Associated Attachable Entity Profile drop-down list, choose default.

If you choose to create a new profile, follow the instructions in the section "Configuring anAttachable Entity Profile" in the Cisco Application Virtual Switch Configuration Guide.

2 In the AVS Fabric-Wide Multicast Address field, enter 225.1.1.1.

3 From the Pool of Multicast Addresses (one per-EPG) drop-down list, choose CreateMulticast Address Pool.

4 In the Create Multicast Address Pool dialog box, in the Name field, enter a name.

5 In the Address Blocks area, click the + icon.

6 In the Create Multicast Address Block dialog box, enter the multicast IP address range, forexample 225.0.0.50 to 225.0.0.100, and then click OK.

7 In the dialog box, click SUBMIT.

NoLocal Switching

In the Create vCenter Domain dialog box, complete the following actions:

1 In the Encapsulation area, click the VLAN radio button.

2 From the Associated Attachable Entity Profile drop-down list, choose default.

If you choose to create a new profile, follow the instructions in the section "Configuring anAttachable Entity Profile" in the Cisco Application Virtual Switch Configuration Guide.

3 From the VLAN Pool drop-down list, choose Create VLAN Pool.

4 In the Create VLAN Pool dialog box, in the Name field, enter a name.

5 In the Allocation Mode area, click the Dynamic Allocation radio button.See the Cisco APIC Getting Started Guide for information about dynamic and static pools ina VM management system.

6 In the Encap Blocks area, click the + icon.

7 In the Create Ranges dialog box, in the Range area, type the numbers of the appropriateVLANs in the From and To fields.

8 In the Allocation Mode area, choose Dynamic Allocation, Inherit allocMode from parentor Static Allocation.

VLAN pools can contain encapsulation blocks with different allocation modes. For example,a VLAN pool with dynamic allocation can contain encapsulation blocks with dynamic orstatic allocation.

You must configure an encapsulation block with static allocation if you want toconfigure an EPG with static VLAN port encapsulation. You can use any one of theVLANS in the encapsulation block with static allocation.

Note

9 Click OK.

10 In the Create VLAN Pool dialog box, click SUBMIT.

Local Switchingand you wantVLANencapsulation

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)10

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating a VMware vCenter Domain Profile

Page 11: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

Then...If your switchingpreference is...

In the Create vCenter Domain dialog box, complete the following actions:

1 In the Encapsulation area, click the VXLAN radio button.

2 From the Associated Attachable Entity Profile drop-down list, choose default.

If you choose to create a new profile, follow the instructions in the section "Configuring anAttachable Entity Profile" in the Cisco Application Virtual Switch Configuration Guide.

3 In the AVS Fabric-Wide Multicast Address field, enter 225.1.1.1.

4 From the Pool of Multicast Addresses (one per-EPG) drop-down list, choose CreateMulticast Address Pool.

5 In the Create Multicast Address Pool dialog box, in the Name field, enter a name.

6 In the Address Blocks area, click the + icon and then enter the multicast IP address range,for example 225.0.0.50 to 225.0.0.100.

7 In the Create Multicast Address Block dialog box, er the multicast IP address range, forexample 225.0.0.50 to 225.0.0.100, and then click OK.

8 In the Create Multicast Address Pool dialog box, click SUBMIT.

Local Switchingand you wantVXLANencapsulation

Step 5 In the Create vCenter Domain dialog box, in the vCenter Credentials area, click the + icon.Step 6 In the Create vCenter Credential dialog box, complete the following actions:

a) In the Name field, enter a name.This name identifies a set of VCenter credentials and is used to log into a VCenter instance.

b) In the Username field, enter the vCenter username.c) In the Password field, enter the vCenter password, and then re-enter the password in the Confirm Password field.d) Click OK to save the vCenter credentials.

Step 7 In the Create vCenter Domain dialog box, in the vCenter area, click the + icon.Step 8 In the Create vCenter Controller dialog box, complete the following actions:

a) In the Name field, enter a name.The name identifies a specific vCenter instance.

b) In the Host Name (or IP Address) field, enter the vCenter IP address.c) From the DVS Version drop-down list, choose a DVS version to use in the vCenter or choose vCenter Default.

Choosing vCenter Default configures DVS Version 5.5. DVS version 5.5 supports only Vmware ESXi hosts withversion 5.5. Choose DVS version 5.1 if you want to support Vmware ESXi hosts of version 5.1, 5.5, or 6.0. Forexample, an administrator can choose DVS Version 5.1 with a 5.5 vCenter. However, an administrator with a Version5.1 vCenter should not choose Version 5.5 for the DVS.

d) In the Datacenter field, specify the data center.Make sure that the namematches the data center namewhere the virtual switch was configured in the vCenter.Also, if you are adding more than one Cisco AVS to a vCenter domain, make sure not to add more than oneCisco AVS to each data center.

Note

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10) 11

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating a VMware vCenter Domain Profile

Page 12: Procedures for Creating Interface and Switch Policies and ... · Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain Profile Modifying the Interface

e) If you plan to use a tenant management EPG to access the vCenter, from theManagement EPG drop-down menu,chooseCreate EPGUnder Tenantmgmt and complete the steps in the dialog box. Otherwise, leave theManagementEPG blank.See the Cisco APIC Getting Started Guide for information about management access.

f) From the Associated Credential drop-down list, choose the new vCenter credentials.g) In the vSwitch Policy area, check the appropriate check boxes.

In the vSwitch Policy area, check theMAC Pinning check box if you have a Unified Computing System(UCS) Fabric Interconnect (FI) between the top-of-rack switch and the Cisco AVS.

Note

h) From the Firewall drop-down list, accept the default Learning mode or choose Enabled mode.Learning mode is used only when upgrading from a version of Cisco AVS that does not support Distributed Firewallto a version that does. Otherwise, Distributed Firewall should be in Enabled mode.You can change the DistributedFirewall mode later. See the section "Creating a Distributed Firewall Policy or Changing its Mode Using the AdvancedGUI" in the Cisco ACI Virtualization Guide for instructions.

i) Click OK to save the vCenter Controller.

Step 9 Click SUBMIT to create the vCenter Domain.Step 10 Verify that the new virtual switch appears in the vCenter Client GUI under the folder for the data center. You will also

see uplink and vtep created under the virtual switch.

Cisco Application Virtual Switch Installation Guide, Release 5.2(1)SV3(1.10)12

Procedures for Creating Interface and Switch Policies and Creating a vCenter Domain ProfileCreating a VMware vCenter Domain Profile