Cisco APIC Layer 3 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 3 Networking Configuration Guide, Release 6.2(x)

IP to SR handoff configuration migration

Want to summarize with AI?

Log in

Explains the process of transitioning previously-configured L3Outs from IP handoff configurations to SR handoff configurations using SR-MPLS components.


IP to SR handoff configuration migration is a process that

  • transitions L3Outs from pre-Release 5.0(1) IP handoff configurations to SR-MPLS handoff configurations

  • utilizes the new SR-MPLS components introduced in Cisco APIC Release 5.0(1), and

  • maintains connectivity to the same external network infrastructure throughout the transition.

Migration prerequisites and assumptions

Before beginning the migration process, you must have a previously-configured L3Out using a pre-Release 5.0(1) IP handoff configuration, as described in ACI handoffs prior to release 5.0(1): IP handoff.

The migration assumes that the two handoffs connect to the same external network infrastructure and that an external device can access the ACI fabric using both L3Outs. Currently, external clients can access through the L3Outs used in the IP handoff configuration. After completing the migration procedures, external clients can access through the L3Outs used in the SR-MPLS handoff configuration.

These terms distinguish between the two types of L3Outs:

  • IP-based L3Out: Previously-configured user tenant L3Out using a pre-Release 5.0(1) IP handoff configuration.

  • SR-MPLS L3Out: Newly-configured user tenant L3Out configured using the new SR-MPLS components introduced in Cisco APIC Release 5.0(1).

The migration process includes these overall steps:

  1. Configure the external EPGs on the SR-MPLS VRF L3Out to mirror the IP-based L3Out configuration. This includes the subnets configuration for classification of inbound traffic and the contracts provided or consumed by the external EPGs.

  2. Redirect inbound and outbound traffic to ensure that it starts preferring the SR-MPLS L3Out.

  3. Disconnect the IP-based L3Out.


Configure external EPGs on the SR-MPLS VRF L3Out

Configure external EPGs on the SR-MPLS VRF L3Out to enable migration from IP handoff configuration to SR handoff configuration.
Configure the external EPGs on the SR-MPLS VRF L3Out to mirror the IP-based L3Out configuration that is using a pre-Release 5.0(1) IP handoff configuration. This includes the subnets configuration for classification of inbound traffic and the contracts provided or consumed by the external EPGs.

Before you begin

Review the information provided in IP to SR handoff configuration migration.

Procedure

1.

Create a new infra SR-MPLS L3Out, if you have not done so already.

See Configure an SR-MPLS infra L3Out using the GUI for those instructions, then return here.

2.

Create a new user tenant SR-MPLS L3Out, if you have not done so already.

See Configure an SR-MPLS VRF L3Out using the GUI for those instructions, then return here. Note that this L3Out should be associated to the same VRF of the previously-configured IP-based L3Out.

As part of the process for creating the new user tenant SR-MPLS L3Out, you will be asked to configure the external EPG for this SR-MPLS L3Out.

  • For the external EPG for the new SR-MPLS L3Out, enter the same IP prefix information that you currently have for your previously-configured IP-based L3Out.

  • If you have more than one external EPG configured for your previously-configured IP-based L3Out, create additional external EPGs for the new SR-MPLS L3Out and match the same IP prefix information for each EPG.

In the end, the external EPG settings that you configure for the new SR-MPLS L3Out, with the accompanying subnet settings, should match the external EPG and subnet settings that you had previously configured for the IP-based L3Out.

Once you have completed the procedures for creating the new user tenant SR-MPLS L3Out, you should now have two L3Outs (two paths in BGP):

  • The existing, previously-configured IP-based L3Out that is using a pre-Release 5.0(1) IP handoff configuration, as mentioned in the Before you begin area in IP to SR handoff configuration migration.

  • The new SR-MPLS L3Out that you created using the new SR-MPLS components that have been introduced in Cisco APIC Release 5.0(1).

3.

Ensure the same security policy is applied to the external EPGs of the SR-MPLS L3Out as you had for the IP-based L3Out.

In the non-border leaf switches and the border leaf switches, the new security policy in the external EPG that you configured when you created the new SR-MPLS L3Out will result in a fault for every subnet whose prefix clashes with the subnet prefix in any EPG of the previously-configured IP-based L3Out. This is a fault that does not impact functionality, as long as the same security policies are applied to the same external EPGs of both L3Outs.

The external EPGs are now configured on the SR-MPLS VRF L3Out with matching subnet configurations and security policies from the IP-based L3Out. You now have both L3Outs available for traffic migration.

What to do next

Redirect inbound and outbound traffic to ensure that it starts preferring the SR-MPLS L3Out using the procedures provided in Redirect traffic to SR-MPLS L3Out.


Redirect traffic to SR-MPLS L3Out

Redirect traffic to start preferring the SR-MPLS L3Out instead of the existing IP-based L3Out configuration.
In this task, you will redirect inbound and outbound traffic to ensure that it starts preferring the SR-MPLS L3Out.

Before you begin

Procedure

1.

Navigate to the BGP Peer Connectivity Profile for the previously-configured IP-based L3Out.

In the Navigation pane, navigate to Tenants > tenant_name_for_IP_handoff_L3Out > Networking > L3Outs > L3Out_name > Logical Node Profiles > logical_profile_name > Logical Interface Profiles > logical_interface_profile_name > BGP_peer_connectivity_profile .

2.

Click on the BGP Peer Connectivity Profile in the left nav bar so that the BGP Peer Connectivity Profile page is displayed in the right main window.

3.

Scroll down the page until you see the Route Control Profile area in the BGP Peer Connectivity Profile page.

4.

Determine if route control policies were already configured for the existing IP-based L3Out.

You may or may not have had route control policies configured for the existing IP-based L3Out; however, for the new SR-MPLS L3Out, you will need to have route control policies configured. If you had route control policies configured for the existing IP-based L3Out, you can use those route control policies for the new SR-MPLS L3Out; otherwise, you will have to create new route control policies for the SR-MPLS L3Out.

  • If you see two route control profiles displayed in the Route Control Profile table:

    • An export route control policy, shown with Route Export Policy in the Direction column in the table.

    • An import route control policy, shown with Route Import Policy in the Direction column in the table.

    then route control policies have already been configured for the IP-based L3Out. Go to StepĀ 5.

  • If you do not see two route control profiles displayed in the Route Control Profiles table, then create a new route map that will be used for the SR-MPLS L3Out:

  1. In the Navigation pane, expand the Tenants > tenant_name_for_IP_handoff_L3Out > Policies > Protocol.

  2. Right-click on Route Maps for Route Control and select Create Route Maps for Route Control.

  3. In the Create Route Maps for Route Control dialog box, in the Name field, enter a route profile name.

  4. In the Type field, you must choose Match Routing Policy Only.

  5. In the Contexts area, click the + sign to open the Create Route Control Context dialog box and perform the following actions:

    1. Populate the Order and the Name fields AS desired.

    2. In the Match Rule field, click Create Match Rule.

    3. In the Create Match Rule dialog box, in the Name field, enter a name for the match rule.

    4. Enter the necessary information in the appropriate fields (Match Regex Community Terms, Match Community Terms and Match Prefix), then click Submit.

    5. In the Set Rule field, click Create Set Rules for a Route Map

    6. In the Create Set Rules for a Route Map dialog box, in the Name field, enter a name for the action rule profile.

    7. Choose the desired attributes, and related community, criteria, tags, and preferences. Click Finish.

    8. In the Create Route Control Context window, click OK.

    9. In the Create Route Maps for Route Control dialog box, click Submit.

  6. Navigate to the BGP Peer Connectivity Profile screen:

    Tenants > tenant_name_for_IP_handoff_L3Out > Networking > L3Outs > L3out-name > Logical Node Profiles > logical-node-profile-name > Logical Interface Profiles > logical-interface-profile-name > BGP_peer_connectivity_profile

  7. Click on the BGP Peer Connectivity Profile in the left nav bar so that the BGP Peer Connectivity Profile page is displayed in the right main window.

  8. Scroll down to the Route Control Profile field, then click + to configure the following:

    • Name: Select the route-map that you just configured for the route import policy.

    • Direction: Select Route Import Policy in the Direction field.

    Repeat these steps to select the route-map for the route export policy and set the Route Export Policy in the Direction field.

5.

Force the BGP to choose the new SR path by configuring the route policies for all the peers in the border leaf switches for the VRF that will be undergoing the migration.

  • If the previously-configured IP-based L3Out was configured for eBGP, configure both the route import policy and the route export policy for the IP-based L3Out peer to have an additional AS path entry (for example, the same AS AS local entry). This is the most typical scenario.

    Note

    The following procedures assume you do not have set rules configured already for the route map. If you do have set rules configured already for the route map, edit the existing set rules to add the additional AS path entry (check the Set AS Path checkbox and select the criterion Prepend AS, then click + to prepend AS numbers).

    1. Navigate to Tenant > tenant_name_for_IP_handoff_L3Out > Policies > Protocol > Set Rules and right click Create Set Rules for a Route Map.

      The Create Set Rules For A Route Map window appears.

    2. In the Create Set Rules For A Route Map dialog box, perform the following tasks:

      1. In the Name field, enter a name for these set rules.

      2. Check the Set AS Path checkbox, then click Next.

      3. In the AS Path window, click + to open the Create Set AS Path dialog box.

    3. Select the criterion Prepend AS, then click + to prepend AS numbers.

    4. Enter the AS number and its order and then click Update.

    5. Click OK.

    6. In the Create Set Rules For A Route Map window, confirm the listed criteria for the set rule based on AS Path and click Finish.

    7. Navigate back to the BGP Peer Connectivity Profile screen for this existing IP-based L3Out:

      Tenants > tenant_name_for_IP_handoff_L3Out > Networking > L3Outs > L3out-name > Logical Node Profiles > logical-node-profile-name > Logical Interface Profiles > logical-interface-profile-name > BGP_peer_connectivity_profile

    8. Scroll down to the Route Control Profile area and note the route profile names for both the export route control policy and the import route control policy that are being used for this existing IP-based L3Out.

    9. Navigate to Tenants > tenant_name_for_IP_handoff_L3Out > Policies > Protocol > Route Maps for Route Control.

    10. First locate the export route control profile that is being used for this existing IP-based L3Out and click on that route profile.

      The properties page for this route control profile appears in the main panel.

    11. Locate the route control context entry in the page and double-click the route control context entry.

      The properties page for this route control context appears.

    12. In the Set Rule area, select the set rule that you created earlier in these procedures with the additional AS path entry, then click Submit.

    13. Now locate the import route control profile that is being used for this existing IP-based L3Out and click on that route profile, then repeat these steps to use the set rule with the additional AS path entry for the import route control profile. Doing this will influence inbound traffic, where an external source should start preferring.

  • If the previously-configured IP-based L3Out was configured for iBGP, due to the fact that SR-MPLS only supports eBGP, you will need to use the local preference setting to steer traffic to an eBGP-configured SR-MPLS L3Out, AS described in the previous bullet. Configure both the route import policy and the route export policy for the IP-based L3Out peer to have a lower local preference value:

    1. Navigate to Tenant > tenant_name_for_IP_handoff_L3Out > Policies > Protocol > Set Rules and right click Create Set Rules for a Route Map.

      The Create Set Rules For A Route Map window appears.

    2. In the Name field, enter a name.

    3. Check the Set Preference checkbox.

      The Preference field appears.

    4. Enter the BGP local preference path value.

      The range is 0-4294967295.

    5. Click Finish.

    6. Navigate back to the BGP Peer Connectivity Profile screen for this existing IP-based L3Out:

      Tenants > tenant_name_for_IP_handoff_L3Out > Networking > L3Outs > L3out-name > Logical Node Profiles > logical-node-profile-name > Logical Interface Profiles > logical-interface-profile-name > BGP_peer_connectivity_profile

    7. Scroll down to the Route Control Profile area and note the route profile names for both the export route control policy and the import route control policy that are being used for this existing IP-based L3Out.

    8. Navigate to Tenants > tenant_name_for_IP_handoff_L3Out > Policies > Protocol > Route Maps for Route Control.

    9. First locate the export route control profile that is being used for this existing IP-based L3Out and click on that route profile.

      The properties page for this route control profile appears in the main panel.

    10. Locate the route control context entry in the page and double-click the route control context entry.

      The properties page for this route control context appears.

    11. In the Set Rule area, select the set rule that you created earlier in these procedures with the BGP local preference path, then click Submit.

    12. Now locate the import route control profile that is being used for this existing IP-based L3Out and click on that route profile, then repeat these steps to use the set rule with the BGP local preference path entry for the import route control profile.

6.

Confirm that traffic is now choosing the SR-MPLS path.

The routing/path selection should be through SR-MPLS (BGP should choose the SR-MPLS path over the IP path). You can monitor the traffic and routes in URIB for each VRF to verify that the SR-MPLS path is selected.

Traffic is successfully redirected to prefer the SR-MPLS L3Out over the IP-based L3Out. The BGP routing process now selects the SR-MPLS path for both inbound and outbound traffic flows.

What to do next

Disconnect the IP-based L3Out using the procedures provided in Disconnect the IP-based L3Out.


Disconnect the IP-based L3Out

Disconnect the IP-based L3Out to complete the migration to SR-MPLS L3Out configuration.
After successfully configuring SR-MPLS L3Out and redirecting traffic, you need to disconnect the IP-based L3Out to finalize the migration process.

Before you begin

Procedure

1.

Clean up the IP paths.

You can clean up the IP paths using one of the following methods:

  • Remove one subnet at a time in the external EPG in the previously-configured IP-based L3Out.

  • Remove the external EPGs in the previously-configured IP-based L3Out.

Either of the methods above will result in the fault being cleared, and the external EPG in the SR-MPLS L3Out will now be deployed.

As part of the process of changing the security policy from the IP-based L3Out to the SR-MPLS L3Out, there might be up to a 15-second drop. After that period, the outbound traffic from ACI to outside will take the SR-MPLS path.

If you see that the previously-configured IP-based L3Out was migrated successfully to the new SR-MPLS L3Out, you can then delete the previously-configured IP-based L3Out.

2.

Determine if you have additional L3Outs/VRFs that you want to migrate to SR-MPLS.

Repeat the procedures in IP to SR handoff configuration migration to migrate other user L3Outs and VRFs to SR-MPLS.

The same procedures in IP to SR handoff configuration migration can also be used to migrate between a tenant GOLF L3Out and a tenant SR-MPLS L3Out.

The IP-based L3Out is successfully disconnected and the migration to SR-MPLS L3Out configuration is complete.