Global VLANs
Global VLANs
Cisco UCS Central enables you to define global VLANs in a LAN cloud at the domain group root, or at the domain group level. You can create a single VLAN or multiple VLANs in one operation.
Global VLAN resolution takes place in Cisco UCS Central prior to global service profiles deployment. If a global service profile references a global VLAN, and that VLAN does not exist, the global service profile deployment fails in the Cisco UCS domain due to insufficient resources. All global VLANs created in Cisco UCS Central must be resolved before deploying that global service profile.
Global VLANs are pushed to Cisco UCS domain along with the global service profiles that reference them. Global VLAN information is visible to Cisco UCS Manager only if a global service profile with reference to a global VLAN is deployed in that Cisco UCS domain. When a global VLAN is deployed and becomes available in the Cisco UCS domain, locally-defined service profiles and policies can reference the global VLAN. A global VLAN is not deleted when a global service profile that references it is deleted.
Note | You must have created the VLAN in Cisco UCS Central prior to publishing it to push it down to Cisco UCS Manager. |
Note | If a VLAN group is used to allow VLANs on a Fabric Interconnect’s uplink, the global VLAN must be manually published to Cisco UCS Manager and added to the VLAN group, prior to adding to the service profile assigned to the Cisco UCS domain. If the global VLAN is not published and added to the VLAN group, the vNIC will shut down as the uplink will not allow the global VLAN to pass through. |
Note | A global VLAN is not deleted when a global service profile that references it is deleted. |
You cannot delete a global VLAN from Cisco UCS Manager. If you want to delete a global VLAN from Cisco UCS Manager, you have to localize the VLAN and then delete it.
VLAN Org Permission
All VLANs configured in Cisco UCS Central are common to the orgs in which they are created. You must assign organization permissions before the Cisco UCS Manager instances that are part of the organizations can consume the resources. When you assign org permission to a VLAN, the VLAN is visible to those organizations, and available to be referenced in service profiles maintained by the Cisco UCS Manager instances that are part of the organization.
VLAN name resolution takes place within the hierarchy of each domain group. If a VLAN with the same name exists in multiple domain groups, the organization permissions are applied to all VLANs with the same name across the domain groups.
You can create, modify or delete VLAN org permission.
Note | Make sure to delete the VLAN org permission from the same org you created it in. On Cisco UCS Central GUI you can view the org structure where this VLAN is associated. But at the sub org level on the Cisco UCS Central CLI, you cannot view the VLAN org permission association hierarchy, so if you try to delete the VLAN at the sub org level on the Cisco UCS Central CLI the delete operation will fail. |
Creating or Editing a VLAN
You can create a VLAN at the domain group root or at a specific domain group level, and specify the orgs that can access the VLAN.
You can edit theVLAN ID, Multicast Policy and access for control for any selected VLANs. After creating a VLAN in a domain group, you can not change the Domain Group Location or the VLAN Name.
To watch a video on creating a VLAN, see Video: Creating a VLAN and Assigning Org Permission.
Creating or Editing a VLAN Range
Managing VLAN Access
From the Manage VLAN Access dialog box, you can add or remove permissions to one or more VLANs at the same time.
Note | You can only add or remove access each time you open the dialog box. If you want to do both actions, you will need to relaunch the dialog box. |