Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

PDF

Cisco Catalyst SD-WAN Multitenancy Guide, Releases 26.x and Later

Create a resource profile (tier)

Want to summarize with AI?

Log in

Describes how a provider admin creates a resource profile, formerly called a tier, to set tenant resource limits for multitenant WAN edge devices. It covers maximum VPNs, optional NAT and route limits, warning thresholds, allowed transport TLOCs, color and encapsulation settings, and device-specific VPN limits.


Before you begin

Follow these steps to create a resource profile (previously called a tier).

Procedure

1.

Log in to Cisco SD-WAN Manager as the provider admin user.

2.

From the Cisco SD-WAN Manager menu, choose Administration > Tenant Management.

3.

Click Resource Profiles.

In Cisco vManage Release 20.11.1 and earlier releases, Resource Profiles is called Tiers.

Any existing tiers are displayed in a table.

4.

Click Add a Resource Profile.

In Cisco vManage Release 20.11.1 and earlier releases, Add a Resource Profile is called Add Tier.

5.

In the Add Tier slide-in pane, do this:

  1. Enter these details:

    Field

    Description

    Resource Profile Name

    In Cisco vManage Release 20.11.1 and earlier releases, Resource Profile Name is called Tier Name.

    Enter a unique name for the tier.
    Maximum VPN

    Enter the maximum number of VPNs that can be created on a multitenant WAN edge device for a tenant assigned to this tier.

    Minimum value: 1

    Maximum value: The maximum number of VPNs that you can specify for a tier depends on the device model.

    NAT Limit (Optional)

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.12.1a and Cisco Catalyst SD-WAN Manager Release 20.12.1

    Enter the maximum number of NAT translations that are allowed on each tenant.

    Route Limit (Optional)

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    (Optional) Specify IPv4 unicast or IPv6 unicast route limits. Route limit on a tenant is the sum of routes from all VRFs.

    Default value is 0.

    Note

    The value 0 means there is no route limit configured in the tier definition.

    Route Limit Type

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    The following two route limit types can be configured for IPv4 or IPv6 routes on the device:

    • Warning-only: This option allows to install new tenant IPv4 or IPv6 routes even after total exceeds their respective limit. A warning message is shown on device console when IPv4 route limit or IPv6 route limit is exceeded.

    • Warning with threshold: This option allows to configure a warning threshold, which is the percentage of the route limit. A warning message is shown on device console when the threshold percentage of IPv4 route limit or IPv6 route limit is reached. When a tenant’s total IPv4 or IPv6 routes exceed the configured IPv4 or IPv6 route limit, routes are rejected.

    Threshold

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    Specify the route limit threshold value when you chose Warning with threshold option. When threshold percentage of IPv4 or IPv6 route limit is reached, a warning message is displayed on the device console.

    Range: 1 to 100.

    Allowed Transport

    In Cisco vManage Release 20.11.1 and earlier releases, Allowed Transport is called TLOC.

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    Add TLOC details for the tier. For a tier, add at least one TLOC and up to 16 TLOCs. A TLOC definition includes the TLOC color and the encapsulation type.

    Range: 1 to 16

    Color

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    Select the color from the drop-down list. The color attribute helps to identify an individual WAN transport tunnel.

    Encapsulation

    Minimum supported release: Cisco IOS XE Catalyst SD-WAN Release 17.10.1a and Cisco vManage Release 20.10.1

    Select encapsulation type as either GRE or IPSec per TLOC configuration.

    Table 1. Maximum number of VPNs supported by each device model

    Device model

    Maximum number of VPNs

    ASR1001-X 80
    ASR1001-HX 336
    ASR1002-X 336
    ASR1002-HX 336
    C8500-12X4QC 336
    C8500-12X 336
    C8500L-8S4X 336
    C8300-1N1S-6T 200
    C8300-1N1S-4T2X 200
    C8300-2N2S-6T 200
    C8300-2N2S-4T2X 200
    Catalyst 8000V 300
    ISR4461 80
  2. To add the tier, click Save. To discard your entries and close the slide-in pane, click Cancel.

    After you click Save, the slide-in pane is closed and the new tier is listed in the table along with any existing tiers.