First Time Setup Wizard

This chapter contains the following sections:

First time setup wizard

The First Time Setup wizard is a configuration tool that sets up your Cisco APIC for the first time.

Access methods

You can access the First Time Setup wizard through these methods:

  • Automatically appears the first time you log into your Cisco APIC through the GUI.

  • For Cisco APIC Releases 4.2(3) and later, click the System Tools icon ( ) in the upper right corner of the Cisco APIC GUI window, then select What's New in APIC_release_number.

The Welcome to APIC window appears, providing information on the new features that are part of this particular release.

To access the First Time Setup wizard, click Begin First Time Setup or Review First Time Setup at the bottom right of the window. The Let's Configure the Basics window appears, with links to the individual pages that you can use to set up your Cisco APIC.

When you have completed the initial setup that includes at least one BGP route reflector, the Proceed to Summary button is enabled. Click this button to view summary tiles of the configuration. Additional tiles appear under the heading You Might Want To.... These additional topics are optional but recommended.

Register fabric membership

Register leaf and spine switches to establish fabric membership in your ACI environment. Registration allows switches to become active participants in the fabric topology.

Use the Fabric Membership window to register the leaf and spine switches detected by the ACI fabric. You can also manually add leaf and spine switches to the fabric using the serial number listed on the box.


Note


We recommend registering at least two leaf switches and two spine switches. You must register at least one leaf switch and one spine switch in order to proceed through the First Time Setup wizard.


The Fabric Membership window contains two sections:

  • Discovered: This section provides information on newly-discovered but unregistered switches. These nodes will have a node ID of 0 and will have no IP address.

  • Registered: This section provides information on all of the registered switches in your ACI fabric.

Before you begin

Follow these steps to register fabric membership:

Procedure


Step 1

Register a switch using one of these methods:

  • If the switch is shown in the Discovered section, click the Register button next to that switch to open the Create Fabric Node Member window. Note that the Pod ID and Serial Number fields will be automatically populated in the Create Fabric Node Member window in this case.
  • If the switch is not shown in the Discovered section, click the Action icon ( The image illustrates the steps to register fabric membership, highlighting the creation of fabric node member fields. ), then select Create Fabric Node Member from the drop-down list.

Step 2

In the Create Fabric Node Member window, enter the required information:

Table 1. Create fabric node member fields

Field

Setting

Pod ID

Identify the pod where the node is located.

Serial Number

Required: Enter the serial number of the switch.

Node ID

Required: Enter a number greater than 100. The first 100 IDs are reserved for APIC appliance nodes.

Note

 

We recommend that leaf nodes and spine nodes be numbered differently. For example, number leafs in the 100 range (such as 101, 102) and number spines in the 200 range (such as 201, 202).

Note

 

After the node ID is assigned, it cannot be updated. After the node has been added to the Registered Nodes tab table, you can update the node name by right-clicking the table row and choosing Edit Node and Rack Name.

Switch Name

The node name, such as leaf1 or spine3.

Node Type

Choose the assigned node role. The options are:

  • leaf

    Check one of these boxes if applicable:

    • Is Remote

    • Is Virtual

    • Is Tier-2 Leaf

  • spine

    Check this box if applicable:

    • Is Virtual

  • unknown

Step 3

Click Submit when you have completed the information in the Create Fabric Node Member window.

Step 4

Click Continue in the Fabric Membership window to continue to the next window in the First Time Setup wizard.


The switches are registered and added to the fabric membership. Registered switches appear in the Registered section with assigned node IDs and IP addresses.

Management

Use the Out Of Band Management window to configure the management interface IP address for leaf switches, spine switches, and APIC nodes to connect to the Out of Band (OOB) network. Select several nodes to begin assigning IP addresses to them.


Note


The First Time Setup wizard helps with configuring nodes that have not already been configured for Out of Band management.


Type the address of the gateway in these fields and an IP address is automatically suggested for each discovered node:

  • IPv4 Gateway: The IPv4 default gateway address for communication to external networks using out-of-band management.

  • IPv6 Gateway: The IPv6 default gateway address for communication to external networks using out-of-band management.

In the Filter by attributes area, you can filter the discovered nodes by their attributes. Click Edit if you want to change the nodes that you had selected to configure for Out of Band management.

Click Save to continue to the next window in the First Time Setup wizard.

vPC pairs

Use the Setup - vPC Pairs window to explicitly configure member nodes of the group by using a Fabric policy node endpoint.

In the Filter by attributes area, you can filter the vPC pairs by their attributes. Click Edit if you want to change the vPC pairs that you had selected to configure the vPC pair.

In the vPC Pairs central pane, expand the Actions drop-down list, and choose Create vPC Leaf Switch Pair, Delete vPC Leaf Switch Pair, Download All, or Open in Object Store Browser.

Click Save to continue to the next window in the First Time Setup wizard.

Configure BGP route reflectors

Configure ACI fabric route reflectors to distribute external routes within the fabric using multiprotocol BGP (MP-BGP).

Once you have enabled the route reflectors in the ACI fabric, you can configure connectivity to external networks. You must configure at least one route reflector in order to proceed through the First Time Setup wizard.

Before you begin

Select spine switches to configure as route reflectors.


Note


If you do not see any spine switches in the table in this window, verify that the switch is registered with the correct type or has been discovered by APIC.


Procedure


Step 1

In the BGP window, check the box next to the spine switches that you want to use as route reflectors.

Step 2

Enter the ASN for this spine switch in the Autonomous System Number field.

Step 3

Click Save and Continue.


You continue to the next window in the First Time Setup wizard with the route reflectors configured.

Configure DNS servers and search domains

Configure DNS servers and search domains to allow leaf switches, spine switches and APIC nodes to query DNS names.

Use the DNS window to configure DNS servers and search domains. The OOB connection will be used for DNS communication.


Note


The First Time Setup wizard configures DNS servers and DNS domains under the default DNS Policy.


Procedure


Step 1

To configure the DNS servers, click + in the DNS Servers area.

Step 2

Enter the following information:

  • Address: Enter the provider address.

  • Preferred: Check the check box if you want to have this address as the preferred provider.

  • Status: Provides the status of the configuration request.

Step 3

Click Update, then repeat this process to configure additional DNS servers, if necessary.

Step 4

To configure the search domains, click + in the Search Domains area.

Step 5

Enter the following information:

  • Name: Enter the domain name (cisco.com).

  • Default: Check the check box to make this domain the default domain. You can have only one domain name as the default.

  • Status: Provides the status of the configuration request.

Step 6

Click Update, then repeat this process to configure additional search domains, if necessary.

Step 7

To delete an entry either from the DNS Servers table or from the Search Domains table, select the entry that you would like to delete, then click the trash can icon in that table.

Step 8

Click Save and Continue to continue to the next window in the First Time Setup wizard.


DNS servers and search domains are configured, allowing network devices to query DNS names through the OOB connection.

Configure NTP settings

Configure NTP settings to synchronize leaf switches, spine switches, and APIC nodes to a valid time source and establish proper timekeeping across the network infrastructure.

The NTP window is used during the First Time Setup wizard to configure time synchronization. The OOB connection will be used for NTP communication, and the First Time Setup wizard configures servers under the default NTP Policy.


Note


The First Time Setup wizard configures servers under the default NTP Policy.


Procedure


Step 1

In the Display Format area, select the time display format.

  • Click local to display the date and time in a local time zone format.
  • Click UTC to display the date and time in the UTC time zone format.

The default is local.

Step 2

If you selected local above, in the Time Zone area, click the drop-down arrow to choose the time zone for your domain.

You can also type in the drop down menu area to filter the drop down options. The default is Coordinated Universal Time.

Step 3

To configure the NTP servers, click + in the NTP Servers area.

Step 4

Enter the following information for each NTP server:

  • Host Name/IPAddress: Enter the host name and IP address of the NTP server.

  • Preferred: If you are creating multiple providers, check the Preferred check box for the most reliable NTP source.

  • Status: Provides the status of the configuration request.

Step 5

Click Update, then repeat this process to configure additional NTP servers, if necessary.

Step 6

To delete an entry from the NTP Servers table, select the entry that you would like to delete, then click the trash can icon in that table.

Step 7

Click Save and Continue to continue to the next window in the First Time Setup wizard.


The NTP configuration is saved and the First Time Setup wizard proceeds to the next configuration window. The configured NTP servers will synchronize the time across all leaf switches, spine switches, and APIC nodes in the domain.

Proxy

A proxy is a configuration window that enables setup of HTTP or HTTPS proxy policies for Cisco Cloud Application Policy Infrastructure Controller (APIC) features requiring internet access.

Proxy configuration details

When configured, APIC features that need internet access such as Cisco Intersight connectivity send the traffic through the HTTP or HTTPS proxy. For more information, see the Cisco APIC System Management Configuration Guide.

Global configurations

Use the Global Configurations window to configure certain areas, which we recommend as best practices during the first time set up of your Cisco Application Centric Infrastructure (ACI) fabric. Click Okay, Got it! when you are ready to configure these areas:


Note


Some settings in this window are configurable after the First Time Setup, such as the Subnet Check and Domain Validation settings, which can be configured in the Fabric Wide Setting Policy page (System > System Settings > Fabric-Wide Settings). However, configuring those settings after the First Time Setup might cause issues with other existing configurations. For example, enabling the Enforce Subnet Check and Enforce Domain Validation settings in the Fabric Wide Setting Policy page could break a configured L3Out connection without the proper policy chain in place for the interface or for a statically-assigned port to an EPG.


Subnet check

This feature disables IP address learning outside of subnets configured in a VRF instance, for all other VRF instances.

This feature enforces subnet checks at the VRF instance level, when the Cisco ACI learns the IP address as an endpoint from the data plane. If you put a check in the box for this option, the fabric will not learn IP addresses from a subnet other than the one configured on the bridge domain. This feature prevents the fabric from learning endpoint information in this scenario.

Put a check in the box next to Enforce to enable the subnet check feature, which we highly recommend.

Domain validation

This feature enforces a validation check if a static path is added but no domain is associated to an EPG.

When enabled, a validation check is performed when a static path is added to an EPG, to determine if the path is part of a domain that is associated with the EPG. The scope of this policy is fabric-wide. After configuration, a policy is pushed to each leaf switch as it comes up.

Put a check in the box next to Enforce to enable the domain validation feature, which is highly recommended.

Intermediate system to intermediate system for redistributed routes

This is the IS-IS metric that is used for all imported routes into IS-IS. Configuring a metric lower than 64 (max) with this option, such as 63, allows Cisco ACI switches to prefer routes from stable spines until the routing convergence is achieved on a new spine.

Enter the appropriate value in the IS-IS metric field.

IP aging administrative state

Enabling this policy allows Cisco ACI to track each IP address individually and age out unused addresses efficiently. Otherwise, unused IP addresses remain learned until the base MAC address ages out. This does not affect remote endpoints.

When enabled, the IP aging policy ages unused IP addresses on an endpoint. In this situation, the IP aging policy sends ARP requests (for IPv4) and neighbor solicitations (for IPv6) to track IP addresses on endpoints. If no response is given, the policy ages the unused IP addresses.

These are the options for this field:

  • Disabled: The default setting. Cisco APIC disregards the IP aging policy.

  • Enabled: Cisco APIC observes the IP aging policy.

We highly recommend enabling this feature.

Rogue endpoint control

A rogue endpoint can attack leaf switches through frequently, repeatedly injecting packets on different leaf switch ports and changing 802.1Q tags (emulating endpoint moves), resulting in IP and MAC addresses being learned rapidly in different EPGs and ports. Misconfigurations can also cause frequent IP and MAC address changes (moves).

The rogue endpoint control feature addresses this vulnerability. Enabling this policy allows Cisco ACI to detect and delete unauthorized endpoints.

These are the options for this field:

  • Disabled: The default setting. Cisco APIC disregards the rogue endpoint control policy.

  • Enabled: Cisco APIC observes the rogue endpoint control policy.

We highly recommend that you enable this feature.

Additional settings for rogue endpoint control, such as Rogue EP Detection Interval, Rogue EP Detection Multiplication Factor, and Hold Interval, are available through the Endpoint Controls panel. To access the Endpoint Controls panel, on the menu bar, click System > System Settings > Endpoint Controls, then click the Rogue EP Control tab.

These are the valid and default settings for the fields in the Rogue EP Control tab in the Endpoint Controls window:

  • Rogue EP Detection Interval: Valid values are from 0 to 65535 seconds. Default value is 60.

  • Rogue EP Detection Multiplication Factor: Valid values are from 2 to 65535. Default value is 4.

  • Hold Interval: In the 5.2(1) and 5.2(2) releases, the valid values are from 1800 to 3600 seconds. Beginning with the 5.2(3) release, the valid values are from 300 to 3600 seconds. The default value is 1800.

COOP group policy

Council of Oracle Protocol (COOP) is used to communicate the mapping information (location and identity) to the spine proxy. A leaf switch forwards endpoint address information to the spine switch 'Oracle' using Zero Message Queue (ZMQ). COOP running on the spine nodes will ensure all spine nodes maintain a consistent copy of endpoints and location information in the mapping database.

COOP protocol supports two ZMQ authentication modes:

  • Compatible Type: The default setting. COOP accepts both MD5 authenticated and non-authenticated ZMQ connections for message transportation.


    Note


    The Cisco APIC manages the token used as MD5 password for COOP. This token is automatically rotated by Cisco APIC every hour. This token cannot be displayed.


  • Strict Type: COOP allows MD5 authenticated ZMQ connections only.

We highly recommend the Strict Type setting for the COOP group policy.