Posts for: #Cisco

Service Graph Rendering Expectations vs Reality

Creating a Service Graph Template, applying it and not finding any faults is one thing. Seeing the rendered Service Graph is another thing.

Observation

The rendering of a Service Graph Template is dependent on the following:

  • existence of two EPGs with a contract relationship,
  • existence of an association between the contract and the Service Graph
  • existence of contract-matching traffic, i.e. the existence of traffic that matches that contract. As soon as that contract is attached to the Service Graph Template during the “Apply Service Graph Template” phase, then that is the moment where the Service Graph Instance appears in the APIC GUI.

Critique

When I look for the requirements for deploying Service Graph Redirects in the ACI Service Graph Whitepaper document, the assumption mentioned in the ‘Configuration’ paragraph reads a bit vague: SGR config requirements The activation condition of a Service Graph Template remains open and can only be clarified with these questions:

[Read more]

ACI L4-7 Logical Device

L4-7 Device == L4-7 Cluster Device == Logical Device. This is where we inform ACI about our firewall, ADC, etc. ACI considers service devices as part of application design. That is why we place their functions in EPG pairs or ESG pairs. sc1 The L4-7 Device == the Cluster Device == Logical Device: the ACI logical representation of one or more Concrete Devices that perform the same Service Type. Re-use of a L4-7 Device is possible, whether using its same Cluster interfaces or additional ones.

[Read more]

ACI L4-7 Cluster Interfaces

is the logical interfaces of a L4-7 Device Cluster Device. We distinguish Provider Cluster Interfaces and Consumer Cluster Interfaces. The ACI administrator must define them under the Create L4-7 Device page. sc4

Consumer-Side Interface

The Cluster Interface that will attach directly (or indirectly, in case this is not the first L4-7 Device in the Service Graph Template) to the Consumer-side BD.

Provider-Side Interface

The Cluster Interface that will attach directly (or indirectly, in case this is not the first L4-7 Device in the Service Graph Template) to the Provider-side BD. Any Cluster Device will appear as a draggable element when creating a Service Graph Template. sc4 sc5 ❗ ACI does not detect duplicate IP addresses when two Cluster Devices have the same management IP address or VIP.

[Read more]

Common Concepts For Cisco ACI Standard Service Graphs and Service Graph Redirects

These are common concepts for Standard Service Graphs and Service Graph Redirects. Service Graph with L4-7 Device in Go-To mode == L3 Service Graph. L4-7 Device in Go-To mode and the SGT has PBR enabled == L3 PBR Node.

Concepts

L4-7 Service Graph

requires the Service Graph Template

Service Graph Contract

aka SG Contract The contract associated with the Service Graph.

Service Node

referrs to one concrete device. In Cisco litterature the term Service Node is used more than Concrete Device.

[Read more]

ACI and Active-Active Firewall Cluster in Single-Pod and Multi-Pod Designs

ACI Single Pod, Active-Active Firewall Cluster in Go-To Mode

L4-7 Device Config

A single Concrete Device, one or more Concrete Device Interfaces and one or more Cluster Interfaces, depending on the physical topology. See the document Service Graph Design Guide for ACI 5.2 and Later, page=55.

ACI Multi-Pod, Active-Active Firewall Cluster in Go-To Mode

Stretched Active-Active Firewall Cluster in Go-To Mode, in ACI Multi-Pod Designs

Designing cluster nodes in more than one data center is supported by ACI Multi-Pod. Each ACI pod has one or more firewalls in the active role. See the document ACI Multi-Pod and Service Node Integration, page=5.

[Read more]

ACI L4-7 Service Insertion - Active-Standby Firewalls with Standard Service Graphs (SSG) in ACI Multi-Site Designs

Stretched HA Firewall

Cisco supports a stretched Active-Standby firewall system if:

  • ACI operates in layer 2,
  • the firewall operates as the IP default gateway for the endpoints or the firewall operates in Transparent mode or the active and standby nodes are connected with an L3Out.

Independent HA Firewalls

If I have to deploy Active-Standby Firewalls, Cisco recommends to deploy them as independent HA firewalls in the ACI sites (i.e. not across the intersite link)

[Read more]

ACI L4-7 Service Insertion of an Active-Standby Firewall in Go-To Mode in an ACI Single-Pod Design

One concrete device per firewall –> 2 concrete devices under the L4-7 device.

If I have a two-arm firewall design: For all Concrete Devices within a L4-7 Device I must map all Concrete Interfaces of the same direction to the Cluster Interfaces ( #PersoNote symmetrical interface mapping):

  • add one Cluster Interface for the Consumer side and associate it with all Consumer-side interfaces of all [[#Concrete Device]]s,
  • add one Cluster Interface for the Provider side and associate it with all Provider-side interfaces of all [[#Concrete Device]]s.

If I have a one-arm firewall design: add one Cluster Interface that includes both Concrete Interfaces of the firewalls. #verifyThis

[Read more]

ACI L4-7 Service Insertion_Failover Traffic Management

Failover traffic is not managed by L4-7 Service Graphs

See the document ACI Service Graph Design Guide for ACI 5.2 and Later.pdf, page=50.

With the ‘out-of-band’ method

Use the dedicated firewall failover link ports and firewall stateful failover link ports, or designate some ports for that role; Failover traffic and stateful failover traffic are said to be managed ‘out-of-band’

With the ‘in-band’ method

i.e. use the physical network of the data traffic for failover and stateful failover traffic too. When the firewall is attached to ACI, the physical network path of firewall traffic is the ACI fabric.

[Read more]

ACI Multi-Site and Active-Standby Firewall Clusters with Service Graph Redirect

Technology in Nexus Dashboard Orchestrator Equivalent on APIC
define a Service Service Device Cluster L4-7 Device, SGT

EPG-to-EPG PBR contract in ACI multi-site with independent HA-firewalls: I must define the BD subnet also under the consumer EPG and set the no Gateway SVI flag.

Contract Enforcement vs PBR Contract Enforcement vs PBR Policy Enforcement Contract enforcement == zoning rules are deployed to a leaf X. So leaf X takes action on the contract-matched traffic based on the deployed zoning rules. Leaf X is determined according to the Contract Policy Enforcement Locations table in the document ACI Contract Guide White Paper, page=20.

[Read more]

ACI L4-7 Service Insertion: Service Graph Mgmt Modes

There are three ways to manage L4-7 services when we use service graphs. So if no service graph is inserted, we do not talk about these management modes!

[!Abstract] Unless otherwise specified, when Service Graphs are mentioned, then I am referring to the Unmanaged Mode.

Service Graph in Managed Mode (deprecated concept)

aka Service Policy mode: horizontal integration; requires a Device Package.

Device Package

sc1

adding a Device Package

sc2

[Read more]