Configuring Policy Based Redirect

Policy-Based Redirect

Cisco Application Centric Infrastructure (ACI) policy-based redirect (PBR) enables provisioning service appliances, such as firewalls or load balancers, as managed or unmanaged nodes without requiring a Layer 4 to Layer 7 package. Typical use cases include provisioning service appliances that can be pooled, tailored to application profiles, scaled easily, and have reduced exposure to service outages. PBR simplifies the deployment of service appliances by enabling the provisioning consumer and provider endpoint groups to be all in the same virtual redirect and forwarding (VRF) instance.

PBR deployment consists of configuring a route redirect policy and a cluster redirect policy, and creating a service graph template that uses the route and cluster redirect policies. After the service graph template is deployed, use the service appliance by enabling endpoint groups to consume the service graph provider endpoint group. This can be further simplified and automated by using vzAny. While performance requirements may dictate provisioning dedicated service appliances, virtual service appliances can also be deployed easily using PBR.

Creating Layer 4-Layer 7 Policy Based Redirect

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click L4-L7 Policy Based Redirect.

Step 7

Click Add.

Step 8

On the Create Policy Based Redirect screen, complete the following fields:

  • Enter a unique name and description for the Policy Based Redirect.

  • Check the Enable Pod ID Aware Redirection check box to enable pod ID aware redirection and associate the pod IDs with the preferred PBR nodes to program redirect destinations in the leaf switches located in the specific pods.

  • Choose one of the following hashing algorithms:

    • dip—Destination IP address

    • sip—Source IP address

    • sip-dip-prototype—Source IP address, Destination IP address and Protocol Type (also called Symmetric) based algorithm

  • Check the Resilient Hashing Enabled check box to enable resilient hashing for mapping traffic flows to physical nodes and for avoiding the rehashing of any traffic other than the flows from the failed node.

  • Check the Anycast Endpoint check box to enable anycast endpoint.

  • Click Select and check the IP SLA monitoring policy that you want to use for PBR tracking.

  • The Threshold Enable check box appears when you choose an IP SLA monitoring policy. Check this check box to enable threshold when you want to disable the redirect destination group completely and prevent any redirection. When there is no redirection, the traffic is directly sent between the consumer and the provider. The following threshold settings are available:

    • Min Threshold Percent (Percentage) field—Enter the minimum threshold percentage. If the traffic goes below the minimum percentage, the packet is permitted instead of being redirected. The default value is 0. The allowed threshold range is from 0 to 100.

    • Max Threshold Percent (Percentage) field—Enter the maximum threshold percentage. When the minimum threshold is reached, to revert to the operational state, the maximum threshold percentage must be reached first. The default value is 0. The allowed threshold range is from 0 to 100.

    • Threshold Down Action drop-down list—Choose permit action or deny action from the drop-down list to apply the threshold settings on traffic.

Step 9

Click Submit.


Creating Layer 4 - Layer 7 Redirect Health Group

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click L4 L7 Redirect Health Group.

Step 7

Click Add.

Step 8

On the Create L4-L7 Redirect Health Group screen, enter a unique name and description for L4-L7 Redirect Health Group.

Step 9

Click Submit.


When a redirect health group is no longer consumed by the PBR, you can delete the redirect health group. To delete the redirect health group, click the row with the redirect health group on the L4 L7 Redirect Health Group screen and click Delete.

Creating a Destination of Redirect Traffic

Before you begin

The redirect health group that needs to be associated with the redirect traffic is created.

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click L4-L7 Policy Based Redirect.

Step 7

Click the row with the L4-L7 policy-based redirect record that you want to update and click View Details.

Step 8

Click Destination of Redirect Traffic.

Step 9

Click Add.

Step 10

On the Add Destination of Redirected Traffic screen, complete the following fields:

  • Enter the IP address for the Layer 4 to Layer 7 device. The IP address must be in the same subnet as the IP address that you have given to the bridge domain.

  • Enter a short description for the destination of redirected traffic.

  • Enter the MAC address for the Layer 4 to Layer 7 device. You should use a MAC address that is valid upon failover of the Layer 4 to Layer 7 device.

  • Enter the secondary IP address for the Layer 4 to Layer 7 device.

  • Enter the pod identification value. By default, 1 is set as the pod ID. The valid pod ID range is from 1 to 255.

  • Click Select and check the check box for the redirect health group that you want to associate to an existing health group.

Step 11

Click Submit.


Creating an IP SLA Monitoring Policy

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click IP SLA Monitoring Policy.

Step 7

Click Add.

Step 8

On the Create IP SLA Monitoring Policy screen, complete the following fields:

  1. Enter a unique name and description for the IP SLA Monitoring Policy.

  2. In the SLA Frequency field, enter the interval probe time to track a packet. The allowed SLA frequency range is 1 to 65535 seconds. The default value is 60 seconds.

  3. Choose icmp or tcp as the SLA type. If you choose tcp, then enter the SLA port number in the SLA Port field.

Step 9

Click Submit.


vzAny

The vzAny managed object provides a convenient way of associating all endpoint groups (EPGs) in a Virtual Routing and Forwarding (VRF) instance to one or more contracts, instead of creating a separate contract relation for each EPG.

To view vzAny, choose Physical > Network > Multi-Domain Managers > APIC Accounts > Tenant(s) > VRF > vzAny.

Creating a vzAny Provided Contract

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny Provided Contract, and click View Details.

Step 8

Click vzAny Provided Contract.

Step 9

Click Add.

Step 10

On the Add vzAny Provided Contract to VRF screen, complete the following fields:

  1. Click Select and choose the contract that you want to use for the vzAny.

  2. Choose one of the following as the priority level of the quality of service (QoS):

    • Unspecified—Default value.

    • Level3—Class 3 Differentiated Services Code Point (DSCP) value.

    • Level2—Class 2 DSCP value.

    • Level1—Class 1 DSCP value.

  3. Choose one of the following as the match criteria for the provided contract:

    • All—Only matches when both endpoint groups have all labels, excluding blank labels.

    • AtleastOne—At least 1 label matches on Provider and Consumer endpoint groups. Blank labels are considered a match.

    • AtmostOne—Matches only when all labels on the endpoint groups are exactly the same. Blank labels are considered a match.

    • None—None of the subject labels match.

Step 11

Click Submit.


Creating a vzAny Consumed Contract

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny Provided Contract, and click View Details.

Step 8

Click vzAny Consumed Contract.

Step 9

Click Add.

Step 10

On the Add vzAny Consumed Contract to VRF screen, complete the following fields:

  1. Click Select and choose the contract that you want to use for the vzAny.

  2. Choose one of the following as the priority level of the quality of service (QoS):

    • Unspecified—Default value.

    • Level3—Class 3 Differentiated Services Code Point (DSCP) value.

    • Level2—Class 2 DSCP value.

    • Level1—Class 1 DSCP value.

Step 11

Click Submit.


Creating a vzAny Contract Interface

A contract interface is used to associate an EPG from the destination tenant with the imported contract.

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click Tenant(s).

Step 4

Click the row with the tenant that you want to update and click View Details.

Step 5

Click VRF.

Step 6

Click the row with the VRF to which you want to add vzAny contract interface and click View Details.

Step 7

Click vzAny Contract Interface.

Step 8

Click Add.

Step 9

On the Add Contract Interface screen, complete the following fields:

  1. Click Select and check the contract interface that you want to use.

  2. Choose one of the following as the priority level of the service contract:

    • Unspecified—Default value.

    • Level3—Class 3 Differentiated Services Code Point (DSCP) value.

    • Level2—Class 2 DSCP value.

    • Level1—Class 1 DSCP value.

Step 10

Click Submit.


Labels

Labels are managed objects with only one property: a name. Labels enable classifying which objects can and cannot communicate with one another. Label matching is done first. If the labels do not match, no other contract or filter information is processed. The label match attribute can be one of these values: at least one (the default), all, none, or exactly one.

Labels determine which EPG consumers and EPG providers can communicate with one another. Label matching determines which subjects of a contract are used with a given EPG provider or EPG consumer of that contract.

The two types of labels are as follows:

  • Subject labels are applied to EPGs. Subject label matching enables EPGs to choose a subset of the subjects in a contract.

  • Provider or consumer labels are applied to EPGs. Provider or consumer label matching enables consumer EPGs to choose their provider EPGs and vice versa.

Creating a vzAny EPG Consumed Any Labels

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny EPG consumed any label and click View Details.

Step 8

Click vzAny EPG Consumed Any Labels.

Step 9

Click Add.

Step 10

On the Add Consumed Any EPG Label to vzAny VRF screen, complete the following fields:

  1. Enter a unique name for the consumed any label.

  2. From the Label Tag drop-down list, choose a color for the label.

Step 11

Click Submit.


Creating a vzAny EPG Provided Any Labels

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny EPG provided any label and click View Details.

Step 8

Click vzAny EPG Provided Any Labels.

Step 9

Click Add.

Step 10

On the Add Provided Any EPG Label to vzAny VRF screen, complete the following fields:

  1. Enter a unique name for the provided any label.

  2. From the Label Tag drop-down list, choose a color for the label.

  3. Check the Complement check box to enable the complement for the provided any label. By default, the complement is disabled.

Step 11

Click Submit.


Creating APIC vzAny Provided Subject Label to VRF

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny provided subject label and click View Details.

Step 8

Click vzAny Subject Label Provided.

Step 9

Click Add.

Step 10

On the Add APIC vzAny Provided Subject Label to VRF screen, complete the following fields:

  1. Enter a unique name for the provided subject label.

  2. From the Label Tag drop-down list, choose a color for the label.

  3. Check the Complement check box to enable the complement for the provided subject label. By default, the complement is disabled.

Step 11

Click Submit.


Creating APIC vzAny Consumed Subject Label to VRF

Procedure


Step 1

Choose Physical > Network.

Step 2

On the Network page, choose the account under Multi-Domain Managers.

Step 3

Click the row with the APIC account and click View Details.

Step 4

Click Tenant(s).

Step 5

Click the row with the tenant that you want to update and click View Details.

Step 6

Click VRF.

Step 7

Click the row with the VRF to which you want to add vzAny consumed subject label and click View Details.

Step 8

Click vzAny Subject Label Consumed.

Step 9

Click Add.

Step 10

On the Add APIC vzAny Consumed Subject Label to VRF screen, complete the following fields:

  1. Enter a unique name for the consumed subject label.

  2. From the Label Tag drop-down list, choose a color for the label.

  3. Check the Complement check box to enable the complement for the consumed subject label. By default, the complement is disabled.

Step 11

Click Submit.