Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Configure FCoE connectivity without policies or profiles using the NX-OS style CLI

Want to summarize with AI?

Log in

Configure FCoE connectivity for an EPG under a tenant without configuring or applying switch-level and interface-level policies and profiles using NX-OS style CLI commands.


This task configures FCoE connectivity for EPG e1 under tenant t1 without configuring or applying switch-level and interface-level policies and profiles.

Use this configuration when you need to establish FCoE connectivity using NX-OS style CLI sequences for a specific EPG and tenant combination without the complexity of additional policies and profiles.

Procedure

  1. Under the target tenant configure a bridge domain to support FCoE traffic.

    The sample command sequence creates bridge domain b1 under tenant t1 configured to support FCoE connectivity.

    Example:

    apic1(config)# tenant t1
    apic1(config-tenant)# vrf context v1
    apic1(config-tenant-vrf)# exit
    apic1(config-tenant)# bridge-domain b1
    apic1(config-tenant-bd)# fc
    apic1(config-tenant-bd)# vrf member v1
    apic1(config-tenant-bd)# exit
    apic1(config-tenant)# exit
  2. Under the same tenant, associate the target EPG with the FCoE-configured bridge domain.

    The sample command sequence creates EPG e1 and associates that EPG with the FCoE-configured bridge domain b1.

    Example:

    apic1(config)# tenant t1
    apic1(config-tenant)# application a1
    apic1(config-tenant-app)# epg e1
    apic1(config-tenant-app-epg)# bridge-domain member b1
    apic1(config-tenant-app-epg)# exit
    apic1(config-tenant-app)# exit
    apic1(config-tenant)# exit
  3. Create a VSAN domain, VSAN pools, VLAN pools and VSAN to VLAN mapping.

    In Example A, the sample command sequence creates VSAN domain, dom1 with VSAN pools and VLAN pools, maps VSAN 1 to VLAN 1 and maps VSAN 2 to VLAN 2

    Example:

    A
    apic1(config)# vsan-domain dom1
    apic1(config-vsan)# vsan 1-10
    apic1(config-vsan)# vlan 1-10
    apic1(config-vsan)# fcoe vsan 1 vlan 1 loadbalancing src-dst-ox-id 
    apic1(config-vsan)# fcoe vsan 2 vlan 2

    In Example B, an alternate sample command sequence creates a reusable VSAN attribute template pol1 and then creates VSAN domain dom1, which inherits the attributes and mappings from that template.

    Example:

    B
    apic1(config)# template vsan-attribute pol1
    apic1(config-vsan-attr)#  fcoe vsan 2 vlan 12 loadbalancing src-dst-ox-id
    apic1(config-vsan-attr)#  fcoe vsan 3 vlan 13 loadbalancing src-dst-ox-id
    apic1(config-vsan-attr)#  exit
    apic1(config)#  vsan-domain dom1
    apic1(config-vsan)# vsan 1-10
    apic1(config-vsan)# vlan 1-10
    apic1(config-vsan)# inherit vsan-attribute pol1
    apic1(config-vsan)# exit
  4. Create the physical domain to support the FCoE Initialization (FIP) process.

    In the example, the command sequence creates a regular VLAN domain, fipVlanDom, which includes VLAN 120 to support the FIP process.

    Example:

    apic1(config)# vlan-domain fipVlanDom
    apic1(config-vlan)# vlan 120
    apic1(config-vlan)# exit
  5. Under the target tenant configure a regular bridge domain.

    In the example, the command sequence creates bridge domain FIP-bd.

    Example:

    apic1(config)# tenant t1
    apic1(config-tenant)# vrf context v2
    apic1(config-tenant-vrf)# exit
    apic1(config-tenant)# bridge-domain fip-bd 
    apic1(config-tenant-bd)# vrf member v2
    apic1(config-tenant-bd)# exit
    apic1(config-tenant)# exit
  6. Under the same tenant, associate this EPG with the configured regular bridge domain.

    In the example, the command sequence associates EPG EPG-FIP with bridge domain FIP-bd.

    Example:

    apic1(config)# tenant t1
    apic1(config-tenant)# application a1
    apic1(config-tenant-app)# epg epg-fip 
    apic1(config-tenant-app-epg)# bridge-domain member fip-bd 
    apic1(config-tenant-app-epg)# exit
    apic1(config-tenant-app)# exit
    apic1(config-tenant)# exit
  7. Configure a VFC interface with F mode.

    In example A the command sequence enables interface 1/2 on leaf switch 101 to function as an F port and associates that interface with VSAN domain dom1.

    Each of the targeted interfaces must be assigned one (and only one) VSAN in native mode. Each interface may be assigned one or more additional VSANs in regular mode.

    The sample command sequence associates the target interface 1/2 with:

    • VLAN 120 for FIP discovery and associates it with EPG EPG-FIP and application a1 under tenant t1.

    • VSAN 2 as a native VSAN and associates it with EPG e1 and application a1 under tenant t1.

    • VSAN 3 as a regular VSAN.

    In example B, the command sequence configures a VFC over a vPC with the same VSAN on both the legs. From the CLI you cannot specify different VSANs on each log. The alternate configuration can be carried out in the APIC advanced GUI.

    Example:

    A
    apic1(config)# leaf 101
    apic1(config-leaf)# interface ethernet 1/2
    apic1(config-leaf-if)# vlan-domain member fipVlanDom 
    apic1(config-leaf-if)# switchport trunk native vlan 120 tenant t1 application a1 epg epg-fip 
    apic1(config-leaf-if)# exit                            
    apic1(config-leaf)# exit
    apic1(config-leaf)# interface vfc 1/2
    apic1(config-leaf-if)# switchport mode f
    apic1(config-leaf-if)# vsan-domain member dom1 
    apic1(config-leaf-if)# switchport vsan 2 tenant t1 application a1 epg e1 
    apic1(config-leaf-if)# switchport trunk allowed vsan 3 tenant t1 application a1 epg e2
    apic1(config-leaf-if)# exit

    Example:

    B
    apic1(config)# vpc context leaf 101 102
    apic1(config-vpc)# interface vpc vpc1
    apic1(config-vpc-if)# vlan-domain member vfdom100
    apic1(config-vpc-if)# vsan-domain member dom1 
    apic1(config-vpc-if)# #For FIP discovery
    apic1(config-vpc-if)# switchport trunk native vlan 120 tenant t1 application a1 epg epg-fip
    apic1(config-vpc-if)# switchport vsan 2 tenant t1 application a1 epg e1
    apic1(config-vpc-if)# exit
    apic1(config-vpc)# exit
    apic1(config)# leaf 101-102
    apic1(config-leaf)# interface ethernet 1/3
    apic1(config-leaf-if)# channel-group vpc1 vpc
    apic1(config-leaf-if)# exit
    apic1(config-leaf)# exit

    Example:

    C
    apic1(config)# leaf 101 
    apic1(config-leaf)# interface vfc-po pc1
    apic1(config-leaf-if)# vsan-domain member dom1
    apic1(config-leaf-if)# switchport vsan 2 tenant t1 application a1 epg e1
    apic1(config-leaf-if)# exit
    apic1(config-leaf)# interface ethernet 1/2
    apic1(config-leaf-if)# channel-group pc1
    apic1(config-leaf-if)# exit
    apic1(config-leaf)# exit
  8. Configure a VFC interface with NP mode.

    The sample command sequence enables interface 1/4 on leaf switch 101 to function as an NP port and associates that interface with VSAN domain dom1.

    Example:

    apic1(config)# leaf 101
    apic1(config-leaf)# interface vfc 1/4
    apic1(config-leaf-if)# switchport mode np
    apic1(config-leaf-if)# vsan-domain member dom1
  9. Assign the targeted FCoE-enabled interfaces a VSAN.

    Each of the targeted interfaces must be assigned one (and only one) VSAN in native mode. Each interface may be assigned one or more additional VSANs in regular mode.

    The sample command sequence assigns the target interface to VSAN 1 and associates it with EPG e1 and application a1 under tenant t1. "trunk allowed" assigns VSAN 1 regular mode status. The command sequence also assigns the interface a required native mode VSAN 2. As this example shows, it is permissible for different VSANs to provide different EPGs running under different tenants access to the same interfaces.

    Example:

    apic1(config-leaf-if)# switchport trunk allowed vsan 1 tenant t1 application a1 epg e1
    apic1(config-leaf-if)# switchport vsan 2 tenant t4 application a4 epg e4

FCoE connectivity is configured for the specified EPG and tenant using NX-OS style CLI commands without additional policies or profiles.