Creating and Managing Admin Domains

This chapter has the following sections:

Admin Domain Overview

The Admin Domain feature enables you to partition the data center and define data center pods to group hardware and software VTEPs, Layer 3 gateways, and DCI gateways into administrative domains with similar properties. Admin Domains are independent of each other. You can create an admin domain, and specify certain functional roles within the admin domain. Admin domains are logical groups you create, based on the functional roles, which makes centralized L3 or Distributed L2/L3 deployments flexible and extendable.

Cisco VTS provides the functional roles, which you can use as desired to create the admin domains. You can set the system mode, control protocols, other parameters like replication mode (multicast/ingress), for each admin domain , and also assign devices to each of the functional roles. For example, you can pick certain leafs and put it in one group, and associate certain functional parameters to that group. The following functional roles are available:

  • L2 Gateway

  • L3 Gateway

  • DC Gateway

  • DCI

For the L2 Gateway group you can pick the desired leafs and associate certain functional parameters to that group. Similarly, you can define another L3 gateway group, and you can link between these two groups. All L2 configuration can be pushed into the L2 gateway group; and all L3 configuration can be pushed into L3 gateway group.

You can create an L3 gateway group and can link from the L3 group to the DC gateway. You can have the DCI at the top, and this can be linked to the DC gateway.

The DC gateway can be outside the Admin Domain, and more than one Admin Domains may connect to this. You can have the DC gateway inside an Admin Domain, and connect it to an external DCI.

See for detailed information about creating Admin Domains.

The design validated in this release has:

  • L2/L3 gateway groups in all Admin Domain-Each Admin Domain can have its own L2 / L3 gateway.

  • DC Gateway outside the Admin Domain

  • DCI outside the Admin Domain.

Viewing Admin Domain

The Admin Domains home page lists all the Admin Domains that you have created. It provides the option to create a new Admin Domain.

It also displays the status of the Admin Domains. You can also edit an Admin Domain.

To view admin domains:


    Step 1   Go to Admin Domains > Domains. The Admin Domains / Domains window appears.
    You can see two types of views on the Admin Domain page. The two types of views are as follows:
    • List view

    • Tree view

    Step 2   To view the details of an Admin Domain, click the desired admin domain.

    You can create an Admin Domain from the table. To do this, click the Add (+) icon in the table, and provide the required details. You can also edit or delete an Admin Domain.


    Creating an Admin Domain

    To create an admin domain:

    Before You Begin
    • Ensure that you have created authorization groups populated with the correct credentials.

    • Ensure that you have discovered the topology and imported the CSV file (after assigning / reviewing device roles). See Performing Auto Discovery and Managing Inventory sections for details.


      Step 1   Go to Admin Domains > Domains.

      The Admin Domains / Admins window appears.

      Step 2   Click + Create.

      The Create New Admin Domain popup window appears.

      Step 3   Enter the name and description In the Create New Admin Domain popup window.
      Step 4   Click Create. The Admin Domain canvas appears.
      You can see the following functional groups on the left-hand side of the canvas:

      Functional Group

      Description

      1

      DCI

      DCI is an external gateway.

      2

      DC GW

      DC GW is a border leaf.
      Note   

      If it is a DCI mode, then you need to add DCI device to both the DC GW and DCI.

      In an integrated mode, we need to add DCI to both DC GW functional group and DCI functional group.

      3

      L3 GW

      A group of all L3 devices that can be within an admin domain and that particular device share a particular property or same functionalities.
      Note   

      An admin can create a logical L3 groups and map devices that will exhibit a similar policy behavior under this group.

      4

      L2 GW

      A group of all L2 devices that can be within an admin domain and that particular device share a particular property or same functionalities.
      Note   

      An admin can create a logical L2 groups and map devices that will exhibit a similar policy behavior under this group.

      Step 5   Click the functional group. The functional group icon appears on the canvas. You need to drag and drop the functional group and assign properties to them.

      Functional Group

      Property

      DCI

      • New or Shared DCI.

      DC GW

      • New or Shared DC GW.

      • Control Protocol - BGP EVPN.

      L3 GW

      • New and Shared L3 GW.

      • Control Protocol - BGP EVPN.

      • Replication Mode - Multicast or Ingress. This is the data plane replication mode that will used for VXLAN data plane traffic. The admin domain can contain devices that support common replication mode.
        Note   
        • Cisco Nexus 5600 supports Multicast replication mode only.

        • VTF supports Ingress mode only.
        • Cisco Nexus 9000 supports both modes.

      • Distribution Mode - Decentralized.

        Note    L3 GW group is created as Decentralized when the L2/L3 VXLAN are terminated on the same leaf. Therefore, if you have multiple L2 VXLAN and you want to connect them together using an L3 VXLAN, you need to create a decentralized L3 GW group and add all the L2GW group devices to this L3GW group, and connect the L2 GW and L3 GW group together.

        An L3 GW group can be created as a Decentralized Gateway group when the L3 GW groups are distributed between multiple L2 GW group within an Admin Domain.

      • ARP Suppression - On.

      L2 GW

      • New and Shared L2 GW.

      • Control Protocol - BGP EVPN.

      • Replication Mode - Multicast or Ingress.

      • Distribution Mode - Decentralized.

      • ARP Suppression - On.

      Step 6   Assign Devices for each function group.
      Note   

      If you had created a device group (under Resource Pools > VLAN Pool), the device group information does not get displayed in the device list for DCI and DC GW functional groups, while you create an admin domain. However, the device group gets displayed in the device list for L3 GW and L2 GW functional group.

      Click the icon on the right hand side below Devices that shows how many devices are placed in this group or how many devices can be placed in this group. You can see All option which shows both placed devices and available devices.

      For more information about supported devices, see the Supported Platforms section in the Cisco Virtual Topology System Installation Guide.

      Step 7   Connect or link the functional groups based on your requirement.
      Step 8   Click Save to save the new Admin Domain with all the nodes, properties, and links.

      Click Cancel icon if you want to go back to the main menu.