The Council of Oracle Protocol (COOP) distributes endpoint identity and location information throughout the Cisco ACI fabric.
COOP enables spine switches to maintain a consistent endpoint mapping database for forwarding traffic through the fabric.
Cisco APIC Security Configuration Guide, Release 6.2(x)
The Council of Oracle Protocol (COOP) distributes endpoint identity and location information throughout the Cisco ACI fabric.
COOP enables spine switches to maintain a consistent endpoint mapping database for forwarding traffic through the fabric.
COOP distributes endpoint identity and location information to the spine proxy so that all spine switches maintain a consistent endpoint mapping database.
COOP uses Zero Message Queue (ZMQ) to transport endpoint information from leaf switches to spine switches.
Spine switches that run COOP maintain endpoint identity-to-location mappings in a distributed hash table (DHT).
COOP can use MD5 authentication to prevent unauthorized message injection.
COOP supports the following ZMQ connection authentication modes:
Strict mode —Accepts only MD5-authenticated ZMQ connections.
Compatible mode —Accepts MD5-authenticated and unauthenticated ZMQ connections.
For data-path communication, COOP prioritizes authenticated connections. Cisco APIC and the fabric switches support COOP authentication.
COOP authentication protects the Zero Message Queue (ZMQ) connections that transport endpoint mapping information within the fabric.
COOP supports MD5-authenticated ZMQ connections.
COOP provides compatible and strict authentication modes.
Cisco APIC rotates the security token that supplies the authentication credential every hour.
|
Mode |
Default |
Connection behavior |
|---|---|---|
|
|
Yes |
Accepts MD5-authenticated and unauthenticated ZMQ connections. |
|
|
No |
Accepts only MD5-authenticated ZMQ connections. |
Cisco APIC stores the COOP authentication policy and security token in managed objects in the Data Management Engine (DME) and COOP database.
|
Managed object |
Purpose |
|---|---|
|
|
Configures the authentication mode in the COOP database at |
|
|
Contains the |
Cisco APIC changes the security token every hour in both authentication modes.
The value of the
@tokenattribute is not displayed.
The COOP authentication mode determines whether fabric switches accept authenticated connections only or accept both authenticated and unauthenticated connections.
During a Cisco Application Centric Infrastructure (ACI) fabric upgrade, do not enable strict COOP authentication until all switches in the fabric have been upgraded.
Enabling strict authentication before all switches are upgraded can cause a switch to reject a COOP connection.
If a fabric upgrade is in progress, upgrade all switches in the fabric before selecting strict authentication.
If a fabric upgrade is in progress, upgrade all switches in the fabric before configuring strict authentication.
If a fabric upgrade is in progress, upgrade all switches in the fabric before configuring strict authentication.