New and Changed Information
The following table provides an overview of the significant changes up to this current release. The table does not provide an exhaustive list of all changes or of the new features up to this release.
Cisco APIC Release Version |
Feature |
Description |
Where Documented |
---|---|---|---|
Release 2.1(1h) |
Global toggle between in-band and out-of-band default management connectivity |
A toggle has been added to switch between in-band or out-of-band as the default management connectivity mode between the APIC server and other external management devices. |
This content is available in Toggling between In-band and Out-of-band Default Management Connectivity. |
Release 1.3(1g) |
- |
Removed object model CLI procedures and replaced them with NX-OS Style CLI procedures. |
This content is available in the Configuring Static In-Band Management Access Using the NX-OS Style CLI section and in the Configuring Static Out-of-Band Management Access Using the NX-OS Style CLI section with static management access examples. |
Release 1.2(2g) |
IPv6 configurations supported |
IPv6 configurations are supported using static configurations (for in-band and out-of-band). |
- |
Release 1.0(2j) |
- |
This article was written. |
- |
About Static Management Access
Configuring static in-band and out-of-band management connectivity is simpler than configuring dynamic in-band and out-of-band management connectivity. When configuring in-band static management, you must specify the IP address for each node and make sure to assign unique IP addresses. For simple deployments where users manage the IP addresses of a few leaf and spine switches, it is easy to configure a static management access. For more complex deployments, where you might have a large number of leaf and spine switches that require managing many IP addresses, static management access is not recommended. We recommend that you configure a dynamic management access that automatically avoids the possible duplication of IP addresses.
Guidelines and Limitations for Static Management Access
The following guidelines and limitations apply for static management access:
-
We recommend that you configure either in-band or out-of-band static management or in-band and out-of-band dynamic management. Do not combine the two methods in your deployments.
-
IPv4 and IPv6 addresses are supported for in-band management access. IPv6 configurations are supported using static configurations (for both in-band and out-of-band). IPv4 and IPv6 dual in-band and out-of-band configurations are supported only through static configuration. For more information, see the Configuring Static Management Access in Cisco APIC KB article.
-
Using log directive on filters in management contracts is not supported. Setting the log directive will cause zoning-rule deployment failure.
-
A simple ping to a spine switch will fail if it generates an ARP request, because spine switches do not respond to ARP requests. When pinging a spine switch from the Cisco APIC, you must specify the source interface/address so that the Cisco APIC does not send an ARP request.
-
A spine switch does not resolve ARP on the in-band mangement IP address. Due to this, any device in the in-band management network cannot communicate with the spine switch. Access to a spine switch is only possible over a Layer 3 network.
Static In-band Management
Configuring Static In-Band Management Access Using the GUI
Before you begin
Ensure that enough IP addresses are available to be allocated for the number of nodes that will be required for a deployment.
Procedure
Step 1 |
On the menu bar, choose Work pane, click Configure an Interface, PC, and VPC. . In the |
||
Step 2 |
In the Configure Interface, PC, and VPC dialog box, click the large + icon next to the switch diagram to create a new profile and configure VLANs for the APIC. |
||
Step 3 |
In the Switches field, from drop-down list, check the check boxes for the switches to which the APICs are connected. |
||
Step 4 |
In the Switch Profile Name field, enter a name for the profile. |
||
Step 5 |
Click the + icon to configure the ports. |
||
Step 6 |
Verify that in the Interface Type area, the Individual radio button is selected. |
||
Step 7 |
In the Interfaces field, enter the ports to which APICs are connected. |
||
Step 8 |
In the Interface Selector Name field, enter the name of the port profile. |
||
Step 9 |
In the Interface Policy Group field, from drop-down list, choose Create Interface Policy Group. |
||
Step 10 |
In the Create Access Port Policy Group dialog box, perform the following actions: |
||
Step 11 |
In the Create Attachable Access Entity Profile dialog box, perform the following actions:
|
||
Step 12 |
Expand the Configured Switch Interfaces area to configure the VLANs for the VMM server ports, and perform the following actions: |
||
Step 13 |
Choose Navigation pane, expand to configure the bridge domain on the in-band connection. . In the |
||
Step 14 |
Right-click the in-band bridge domain, click Create Subnet, and perform the following actions: |
||
Step 15 |
On the menu bar, choose Navigation pane, expand , click In-Band EPG - default, and perform the following actions to set the VLAN on the in-band connection: . In the
|
||
Step 16 |
On the menu bar, choose Navigation pane, expand , right-click Node Management Addresses, and click Create Static Node Management Addresses. . In the |
||
Step 17 |
In the Create Static Node Management Addresses dialog box, perform the following actions: The
first node that was ID specified in the node range is allocated with the first
or starting IP address. The next node ID is allocated with the next IP address
and so on sequentially.
|
||
Step 18 |
To verify, in the Navigation pane, expand , and in the Work pane, view the IP addresses allocated for each node.
|
Configuring Static In-Band Management Access Using the REST API
Procedure
Step 1 |
Create a VLAN namespace. Example:
|
Step 2 |
Create a physical domain. Example:
|
Step 3 |
Create selectors for the in-band management. Example:
|
Step 4 |
Configure an in-band bridge domain and endpoint group (EPG). Example:
|
Step 5 |
Create static in-band management IP addresses and assign them to node IDs. Example:
|
Configuring Static In-Band Management Access Using the NX-OS Style CLI
Before you begin
Ensure that enough IP addresses are available to be allocated for the number of nodes that will be required for a deployment.
Procedure
Configure the static in-band management configuration using the NX-OS Style CLI as follows: Example:
|
Static Out-of-Band Management
Configuring Static Out-of-Band Management Access Using the GUI
Before you begin
The APIC out-of-band management connection link must be 1 Gbps.
Procedure
Step 1 |
On the menu bar, choose Navigation pane, expand Tenant mgmt. . In the |
Step 2 |
Right-click Node Management Addresses, and click Create Static Node Management Addresses. |
Step 3 |
In the Create Node Management Addresses dialog box, perform the following actions: The static node management IP addresses are configured.
|
Step 4 |
To verify, in the Navigation pane, expand Node Management Addresses, and click Static Node Management Addresses. In the
Work pane, the node management IDs and assigned
IP addresses are displayed.
|
Step 5 |
In the Navigation pane, expand . |
Step 6 |
Right-click Out-of-Band Contracts, and click Create Out-of-Band Contract. |
Step 7 |
In the Create Out-of-Band Contract dialog box, perform the following tasks:
An out-of-band contract that can be applied to the
out-of-band EPG is created.
|
Step 8 |
In the Navigation pane, expand . |
Step 9 |
In the Work pane, expand Provided Out-of-Band Contracts. |
Step 10 |
In the OOB Contract column, from the drop-down list, choose the out-of-band contract that you created (oob-default). Click Update, and click Submit. The contract is associated with the node management EPG.
|
Step 11 |
In the Navigation pane, right-click External Network Instance Profile, and click Create External Management Entity Instance. |
Step 12 |
In the Create External Management Entity Instance dialog box, perform the following actions: The node management EPG is attached to the external network
instance profile. The out-of-band management connectivity is configured.
|
Configuring Static Out-of-Band Management Access Using the REST API
Before you begin
The APIC out-of-band management connection link must be 1 Gbps.
Procedure
Step 1 |
Create an out-of-band contract. Example:
|
Step 2 |
Associate the out-of-band contract with an out-of-band EPG. Example:
|
Step 3 |
Associate the out-of-band contract with an external management EPG. Example:
|
Step 4 |
Create static out-of-band management IP addresses and assign them to node IDs. CHECK IP Addresses Example:
|
Configuring Static Out-of-Band Management Access Using the NX-OS Style CLI
Before you begin
Ensure that enough IP addresses are available to be allocated for the number of nodes that will be required for a deployment.
Procedure
Configure the static out-of-band (OOB) management configuration using the NX-OS Style CLI as follows: Example:
|
Toggling between In-band and Out-of-band Mangement
Toggling between In-band and Out-of-band Default Management Connectivity
With APIC 2.1(1x), you can set a global toggle between In-band and out-of-band as the default management connectivity between the APIC server and other external management devices.
Toggling in-band or out-of-band management in the APIC GUI
You can make either in-band management access or out-of-band management access the default management connectivity mode for the APIC server.
Prior to Release 2.2(1x):
-
On the menu bar, choose
.In the Connectivity Preferences page, click either inband or ooband.
For Release 2.2(x) and 2.3(x):
-
On the menu bar, choose
.In the APIC Connectivity Preferences page, click either inband or ooband.
For Release 3.0(1x) or later:
-
On the menu bar, choose
.In the APIC Connectivity Preferences page, click either inband or ooband.
Toggling in-band or out-of-band management using the NX-OS Style CLI
apic1# configure
apic1(config)# mgmt_connectivity pref {inband|ooband}
Toggling in-band or out-of-band management using the REST API
You can make either in-band management access or out-of-band management access the default management connectivity mode for the APIC server by posting the following REST API structure:
POST https://APIC-IP/api/node/mo/.xml
<polUni>
<fabricInst>
<mgmtConnectivityPrefs interfacePref=“ooband"/> <!- or "inband" --->
</fabricInst>
</polUni>