- Cisco Nexus Data Broker Overview
- Deploying Cisco Nexus Data Broker
- Managing TLS Certificate, KeyStore, and TrustStore Files
- Logging in and Managing Cisco Nexus Data Broker
- Viewing and Adding Devices
- Configuring Cisco Nexus 9000 Series Switches
- Configuring the Nexus Data Broker
- Integrating Cisco Nexus Data Broker With Cisco ACI
- Viewing and Adding Flows
- Viewing Consistency Check
- Managing Users
- Configuring the Setup for a Use Case in the Centralized Mode
- Managing System
Configuring the
Nexus Data Broker
This chapter contains the following sections:
- Viewing Topology
- Configuring Port Definition
- Configuring Port Groups
- Configuring a Monitoring Device
- Adding a Service Node
- Configuring Symmetric Load Balancing and MPLS Tag Stripping
- Adding Filters
- Adding Connections
- Adding Redirections
- Viewing Statistics
- Adding SPAN Sessions
Viewing Topology
Click the Topology tab in the left frame to view the topology in the network.
Configuring Port Definition
When you click Port Definition tab in the GUI, the Port Definition screen is displayed. Select the switch from the drop-down list to configure the ports.
On the Port Definition screen, the following two tabs are displayed:
Click the Port Configuration tab, the following tabs are displayed:
When you click Configure Multiple Ports tab, the Configure Multiple Ports window is displayed. The following details are displayed on the screen: Number, Status, Port Name, Type, In Use, Port ID, and Action.
![]() Note | Beginning with Cisco Nexus Data Broker, Release 3.1, the interface description is updated from the Cisco Nexus Data Broker GUI to the switch and the interface description is also available from the switch into the Cisco Nexus Data Broker GUI. When using in Openflow mode, the NX-API auxiliary connection is required for this functionality to work. |
![]() Note | On the Port Configuration tab, the port name and the interface are displayed as hyperlinks. When you click the port name, you can view the running configuration for that interface on the tab. |
If you want to remove any ports, select the port and click Remove port Configuration tab.
Click Add Service Node to add a service node.
Click Add Monitoring Device to add a monitoring device.
On the Port Configuration screen, the following port details are displayed for the selected node:
-
Serial Number
-
Status
-
Port name
-
Type
-
In Use
-
Port ID
-
Action—When you click Configure, the Configure Ports window is displayed.
On the SPAN Destination tab, the following details are displayed:
Configuring Ports
Adding SPAN Destination
When you configure a port as an edge SPAN port and the port is connected to the API side, you can select the pod, node, and port from the ACI side and set the port as SPAN destination.
![]() Note | You can add SPAN destination only after APIC has been successfully added to the network. |
| Step 1 | Select the switch for which you want to configure the port details on the Port Configuration screen. |
| Step 2 | Click
Configure under
Action.
The Configure Ports window is displayed. |
| Step 3 | In the
Configure Ports window, configure the port
type from the
Select a port type
drop-down list by selecting one of the following options:
Monitoring Device—Creates a monitoring device for capturing traffic and configures the corresponding delivery port. Edge Port-SPAN—Creates an edge port for incoming traffic connected to an upstream switch that is configured as a SPAN destination. Edge Port-TAP—Creates an edge port for incoming traffic connected to a physical TAP port. Production Port—Creates a production port for the ingress and egress traffic. When you select the port type, the title of the window changes to Manage Configure Ports. |
| Step 4 | In the SPAN DESTINATION pane, select the pod from the Pod drop-down list. |
| Step 5 | Select the ACI leaf from the Leaf drop-down list. |
| Step 6 | Select the port from the ACI side from the Port drop-down list and set the interface as SPAN destination. |
| Step 7 | Click
Submit to save the settings.
The port is now configured as SPAN destination part and it is displayed on the Port Definition screen. |
Configuring Multiple Ports
You can configure multiple ports for a node.
| Step 1 | Click Configure Multiple Ports on the Port Configuration screen. The Configure Multiple Ports window is displayed. |
| Step 2 | Use CTRL/SHIFT to select multiple ports in the Select Ports field. |
| Step 3 | Select port type from the drop-down list in the Select Port Type field. |
| Step 4 | Click Submit to save the settings. |
Configuring Port Groups
You can create a port group and add the ports to the connection.
![]() Note | Starting with Cisco Nexus Data Broker, Release 3.2, you can create port groups for different source ports. The port groups can be a combination of the edge-span and the edge-tap ports across different switches. You can select ports, define port groups, provide a name to the port group, select the port group in a connection screen (only one port group per connection), and use the ports defined in the port group as source ports for creating a connection. Selecting individual ports is disabled when using a port group. You cannot edit the port group even if it is part of a connection. The connection is automatically updated with the new port group. Deleting a port group is not allowed when the port group is in use. |
Complete the following steps to configure port groups:
| Step 1 | Select the switch for which you want to configure the port details on the Port Configuration screen. |
| Step 2 | Click Port Groups tab in the left frame. |
| Step 3 | Click + Add Group to create a port group. |
| Step 4 | In the Create Port Group window, enter the group name in the Group Name field. |
| Step 5 | In the Select Node field, select a node, for example, N9K-116. |
| Step 6 | In the Select Port field, select a port, for example, Ethernet1/1 (Ethernet1/1).
You can add only edge-span and edge-tap ports and you cannot add production ports to the port groups. |
| Step 7 | Click + Add To Group to add the port to the group.
You can add multiple ports to the group. |
| Step 8 | Click Apply.
The port group is displayed on the Port Groups screen with the following information for the group, for example, Name, Connection Name, Ports and Action. |
Configuring a Monitoring Device
| Step 1 | Navigate to the Monitoring Device tab under Configuration. | ||||||||||||||||
| Step 2 | Click + Monitoring Device. | ||||||||||||||||
| Step 3 | In the
Monitoring Device window, complete the following
fields:
| ||||||||||||||||
| Step 4 | Click Save. |
Adding a Service Node
| Step 1 | Navigate to the Service Nodes tab under Configuration and click + Service Node. |
| Step 2 | In the Add Service Node window, enter the name of the service node. |
| Step 3 | Select the ingress port for the service node from the Service Node Ingress Port drop-down list. |
| Step 4 | Select the egress port for the service node from the Service Node Egress Port drop-down list. |
| Step 5 | Enable health check on a service node by selecting the Service Node Health Check option.
Beginning with Cisco Nexus Data Broker, Release 3.2, you can configure the wait interval in the config.ini file before the health check is up. The ServiceNodeHealthCheckWaitInterval is the variable in the config.ini file to set the wait interval. If you do not specify a value or if the value is 0 for the wait interval in the config.ini file, the default value of 5 Seconds is used. The wait interval is not applicable if the port is in shutdown state. This option works only in the OpenFlow mode. The controller or the NDB injects a packet in the service node ingress port and the packet is received at the egress port. The packets are checked at the interval of every 5 seconds. If five packets are not received in 5 seconds, the health of the service node is considered as down. For the service node, a new field is displayed in the details: Service Node Status. This field displays the status of the service node. |
| Step 6 | Select a service node icon from the available options. |
| Step 7 | Click Save. |
Configuring Symmetric Load Balancing and MPLS Tag Stripping
Add device to Cisco Nexus Data Broker using NX-API.
| Step 1 | In the topology diagram, click the node for which you wish to configure MPLS tag stripping. |
| Step 2 | In the Port Configuration window, click Configure Node. The Node Configuration window is displayed. |
| Step 3 | In the Symmetric Load Balancing on Port Channel drop-down list, select the Hashing Option. |
| Step 4 | In the MPLS Strip Configuration drop-down list, choose one of the following:
|
| Step 5 | When you select Enable MPLS Strip option, the Label Age field is displayed. In the field, enter a value for the MPLS strip label age. The range for MPLS strip label age configuration is 61-31622400. |
| Step 6 | Click Submit. |
Adding Filters
The hardware command that is a pre-requisite for the IPv6 feature is hardware access-list tcam region ipv6-ifacl 512 double-wide.
| Step 1 | On the Filters tab, click + Filter to add a filter. The Add Filter window is displayed. | ||||||||||||||||
| Step 2 | In the Filter Description section of the Add Filter window, complete the following fields:
| ||||||||||||||||
| Step 3 | In the Layer 2 section of the Add Filter window, complete the following fields:
| ||||||||||||||||
| Step 4 | In the Layer 3 section of the Add Filter window, update the following fields:
| ||||||||||||||||
| Step 5 | In the Layer 4 section of the Add Filter dialog box, complete the following fields:
| ||||||||||||||||
| Step 6 | In the Layer 7 section of the Add Filter dialog box, complete the following fields:
| ||||||||||||||||
| Step 7 | Click Add Filter. |
Adding Connections
| Step 1 | On the Connections tab, click + Connection. The Add Connections window is displayed. | ||||||||||||||||||||||
| Step 2 | In the Add Connections window, you can add the Connection Name and the Priority of the connection in the Connection Details area:
| ||||||||||||||||||||||
| Step 3 | In the Allow Matching Traffic area, modify the following fields:
| ||||||||||||||||||||||
| Step 4 | In the Drop Matching Traffic area, complete the following fields:
| ||||||||||||||||||||||
| Step 5 | In the Source Ports (Optional) area, complete the following fields:
| ||||||||||||||||||||||
| Step 6 | Do one of the following:
The following fields are displayed on the Connection Setup screen: |
The following fields are displayed In the Connections tab: Status, Name, Allow Filters, Drop Filters, Source Ports/Port Group, Devices, Priority, Last modified by, Description, and Action.
![]() Note | Beginning with Cisco Nexus Data Broker, Release 3.2, if you have added two or more interfaces (source ports) using the Connections tab, two interfaces (source ports) are displayed by default. If you have more than two interfaces (source ports) in the Connections tab, you can expand or collapse the source ports by using more... or less... options that are provided in the GUI. |
Click i Search Connections tab in the Connections screen to search for the connections using the keywords, Success, Installing, Creating, Partial, and Failed.
Adding Redirections
![]() Note | The redirection setup feature is supported on Cisco Nexus 3000 Series switches running Release 6.0(2)U5(2) only and on Cisco Nexus 9300 switches with Release 7.x and OpenFlow. Cisco Nexus Data Broker lets you configure redirection policies that match specific traffic, redirecting it through multiple security tools before it enters or exits your data center using redirection. |
| Step 1 | On the Redirections tab, click + Redirection. The Add Redirection window is displayed. | ||||||||||||||||
| Step 2 | In the Add Redirection window, you can add the Redirection Name and the Priority of the redirection in the Redirection Details area:
| ||||||||||||||||
| Step 3 | In the Matching Traffic area, modify the following fields:
| ||||||||||||||||
| Step 4 | In the Redirection Switch area, modify the following fields:
| ||||||||||||||||
| Step 5 | In the Service Nodes (OPTIONAL) area, complete the following fields:
| ||||||||||||||||
| Step 6 | Select the Reverse ServiceNode Direction option to enable reverse direction on the service node.
When you enable this option and click Submit, the ingress and egress ports of the service node are swapped and reverse redirection is enabled on the service node. The option is also displayed as enabled in the Redirections tab. | ||||||||||||||||
| Step 7 | In the Production Ports area, complete the following fields:
| ||||||||||||||||
| Step 8 | In the Delievery Devices to copy traffic (OPTIONAL) area, complete the following fields:
| ||||||||||||||||
| Step 9 | Do one of the following: | ||||||||||||||||
| Step 10 | When you click Install Redirection to save the redirection and install it at the same time, the redirection path on the redirection switch is displayed on the production ingress ports, service nodes, and the production egress ports. | ||||||||||||||||
| Step 11 | Click Flow Statistics to view the flow statistics for the redirection switch.
The following fields provide information on the flow statistics:
| ||||||||||||||||
| Step 12 | Click Close to close the flow statistics display window. |
Viewing Statistics
View the flow and port statistics for the switches on the Statistics tab.
![]() Note | When you select a switch on the statistics page, the Auto Refresh tab for the switch is ON by default. Click Auto Refresh: Off to disable auto refresh on the Statistics tab. The screen is refreshed every 30 seconds and the updated statistics for the switch are displayed on the screen. |
| Step 1 | Navigate to the
Statistics tab under
Configuration and click a node from the drop-down
list to check and view the flow and port statistics of that node.
You can also navigate to the statistics of another switch by selecting the switch in the drop down box. You can view the flow statistics, for example: | ||
| Step 2 | Click the
Ports tab to check the ports statistics.
You can view the ports statistics as displayed in the following fields.
|
Adding SPAN Sessions
On the SPAN Sessions tab, the following fields are displayed:
You can add a SPAN session in ACI.
| Step 1 | Click + SPAN Session to add a SPAN session. The Add SPAN Session window is displayed. | ||
| Step 2 | In the Add SPAN Session window, add a session name in the SPAN Session Name field. | ||
| Step 3 | (Optional)Select a connection in the Select Connections field. | ||
| Step 4 | In the Action pane, select a priority for the SPAN session. | ||
| Step 5 | Select a rule using the drop-down list in the Rule Filter field. You can select the default filter rule, Default-Match-IP or select another filter from the drop-down list.
The available filter rules are Default-Match-IP, Match-HTTP, Match-vlan, and Default-Match-all. | ||
| Step 6 | Select a destination device to which the traffic is sent. | ||
| Step 7 | In the SPAN SOURCES pane, select the device type as ACI or NXOS in the Select Device Type field. When you select ACI device and click +Add SPAN Source, the Add Leaf Ports or +Add EPG tabs are displayed. | ||
| Step 8 | In the SPAN SOURCES pane, when you select the device type as NXOS in the Select Device Type field and click +Add SPAN Source, the Add Interface or Add VLAN tabs are displayed.
This field allows to add NXOS SPAN session via NXAPI. It allows to add 2 types of SPAN sources. If you need to add interface as source, click + ADD SPAN Source and click Interface. If you need to allow traffic of a particular VLAN, click VLAN.
| ||
| Step 9 | When you click +Add Interface, the Add Production Switch Interface window is displayed.
You can select a node, select an interface, and click Submit. | ||
| Step 10 | When you click +Add VLAN, the Add Production Switch VLAN window is displayed.
You can select a node, enter a VLAN, and click Submit. | ||
| Step 11 | In the SPAN Destination field, you can select the SPAN destination.
This field displays SPAN destination for ACI in the ACI SPAN session or SPAN destination for NXOS in the NXOS SPAN session.
| ||
| Step 12 | Click Add SPAN Session.
A message box is displayed asking you to confirm, Are you sure you want to add SPAN session?, if you want to add the SPAN session. | ||
| Step 13 | Click OK.
As a result, a SPAN session is set up in ACI. It also sets up a connection automatically on the Cisco Nexus Data Broker with the same SPAN session name and this connection redirects the traffic from that source port to the monitoring device.
You can set up additional SPAN sessions. You can append a new SPAN session to the existing connection. In that case, you can select the new SPAN session in the Add SPAN Session window, use the same connection that is previous ly created, select new SPAN sources from different leaf ports, select the SPAN destination, and add the SPAN session. It creates a new session in ACI, but it appends an existing connection to include the new traffic on the Cisco Nexus Data Broker side. You can edit or clone the existing SPAN sessions. If you want to remove a SPAN session, click the session and click Remove SPAN Session(s) A message box is displayed asking you to confirm, Remove the following sessions?, if you want to remove the displayed SPAN session. Click Remove SPAN Sessions to confirm. If the SPAN session is using an existing connection, the connection is updated automatically with the changes. If it is the last connection associated with the SPAN session, the connection is deleted. |

Feedback