Function
|
Parameter
|
Options
|
Description
|
Access Policy
|
*Name
|
<name>
|
Name of the access policy.
|
*Access Rules
|
*Name
|
<name>
|
Name of the access rule.
-
The APIC internally adds a GraphDeploymentSuffix and other information to the Rule comment.
-
Pre-existing FMC Access Rule name must match for the APIC to update with the created Service Graph Security Zones.
|
Source Interface
|
Reference to Interface Object Security Zone
|
—
|
Destination Interface
|
Reference to Interface Object Security Zone
|
—
|
Bi-directional
|
true | false
|
If set to true, applies both Security Zones under Access Rule Source and Destination Zones. Otherwise, Security Zones are
individually applied Source and Destination fields.
|
Security Zone
|
*Name
|
<name>
|
Name of the security zone. Also, APIC folder name of the security zone object, so that other APIC objects can reference it.
The APIC internally adds a GraphDeploymentSuffix to the name. For example, if you select a Security Zone name of External,
on the FMC you'll see a Security Zone named External_<Tenant Name>_<Device Name>.
Note
|
The name field gets saved as <Field Value>_<Tenant Name>_<Device Name> on the FMC which is limited to a total of 48 characters.
Since the GraphDeploymentSuffix can use up to 40 characters, try to limit the name field value to 8 characters.
|
|
*Type
|
INLINE | ROUTED | SWITCHED
|
Type of the security zone.
A mismatched security zone type and interface type are not allowed. It's based on deployment mode.
|
Inline Set
|
*Name
|
<name>
|
Name of the inline set. Also, APIC folder name of the inline set object, so that other APIC objects can reference it.
The APIC internally adds a GraphDeploymentSuffix to the name. For example, if you select an Inline Set name of External, on
the FMC you'll see an Inline Set named External_<Tenant Name>_<Device Name>.
Note
|
The name field gets saved as <Field Value>_<Tenant Name>_<Device Name> on the FMC which is limited to a total of 48 characters.
Since the GraphDeploymentSuffix can use up to 40 characters, try to limit the name field value to 8 characters.
|
|
*MTU
|
<integer>
|
MTU property of the Inline Set.
|
*Snort Fail Open Busy
|
true | false
|
Snort Fail Open Busy property of an Inline Set.
|
*Snort Fail Open Down
|
true | false
|
Snort Fail Open Down property of an Inline Set.
|
Interface
|
*Name
|
<name>
|
APIC folder name of the interface object.
|
*Enabled
|
true | false
|
Enable property of the interface.
|
*MTU
|
<integer>
|
MTU property of the interface.
|
*Logical Name
|
<name>
|
Logical name of the interface (optional unless Inline).
The APIC internally adds a GraphDeploymentSuffix to the name. For example, if you select a Logical Name of External, on the
FMC you'll see a Logical Name of External_<Tenant Name>_<Device Name>.
Note
|
The name field gets saved as <Field Value>_<Tenant Name>_<Device Name> on the FMC which is limited to a total of 48 characters.
Since the GraphDeploymentSuffix can use up to 40 characters, try to limit the name field value to 8 characters.
|
|
*Inline Set
|
Inline Set Object
|
Reference link to the APIC Inline Set folder object.
|
*Security Zone
|
Security Zone Object
|
Reference link to the APIC Security Zone folder object.
|
*IPv4
|
*static
|
*address
|
IPv4 address with subnet mask
|
Applies only to routed interfaces. Values are the IPv4 address with a subnet mask. For example, 1.1.1.1/24
|
Bridge Group Interface
|
*Name
|
<name>
|
APIC folder name of the bridge group interface.
The APIC internally adds a GraphDeploymentSuffix and other information to the description.
|
*IPv4 Address Configuration
|
*static
|
*address
|
IPv4 address with subnet mask
|
Applies only to transparent interfaces. Values are the IPv4 address with a subnet mask. For example, 1.1.1.1/24
|
*Bridge Group ID
|
<integer>
|
—
|
*Interfaces
|
—
|
Reference link to the APIC interface folder object.
|
IPv4 Static Route
|
*Network
|
<network>
|
The foreign network for this route. Must be in A.B.C.D/prefix format. For example, 192.168.1.0/24
|
*Gateway
|
<gateway>
|
The IPv4 address of the gateway by which the foreign network is reached. For example, 192.168.1.1
|
Metric
|
<integer>
|
Distance metric for this route. Valid range is a number between 1 and 255, inclusive.
|
isTunneled
|
true | false
|
—
|
-
For routed-mode FTD, if an IPv4 static route is to be configured, configure it at the physical-interface level. However, if
physical interfaces are put into the BVI interface (IRB feature), configure the IPv4 static route at the BVI-interface level.
-
For transparent-mode FTD, if an IPv4 static route is to be configured, configure it at the physical-interface level, no matter
the BVI configuration.
|