When we try to access 10.1.100.50 (LB IP) from 10.1.100.20 (real server IP), it’s failing. Because CSM is assuming this request from server VLAN to server VLAN. 10.1.100.20 is already defined as a real server for 10.1.100.22 (LB IP).
! vlan 802 server ip address 10.1.100.200 255.255.255.0 alias 10.1.100.202 255.255.255.0 !
Here is the connection output from 10.1.100.20 to 10.1.100.50 (LB IP) :
You will need to have the CSM perform source-NAT on the client connections so that when the servers receive the connection, they see the source address as an IP that the CSM owns. This will force them to send their responses back to the CSM instead of sending them directly back to the locally connected client. See sample config below. Only clients on the server/VIP subnet get source NAT'd. Clients from other subnets will not be NAT'd.:
====================================== On MSFC ====================================== ip access-list standard SERVER-SUBNET permit 10.1.100.0 0.0.0.255
====================================== On CSM ====================================== vlan 20 client ip address 22.214.171.124 255.255.255.0 gateway 126.96.36.199 ! vlan 10 server ip address 10.1.100.1 255.255.255.0 ! natpool SRC-NAT 10.1.100.100 10.1.100.100 netmask 255.255.255.0 ! probe PING icmp ! serverfarm WEB nat server no nat client real 10.1.100.51 inservice real 10.1.100.52 inservice real 10.1.100.33 inservice probe PING ! policy SVR-TO-SVR client-group SERVER-SUBNET nat client SRC-NAT serverfarm WEB ! vserver WEB virtual 10.1.100.50 tcp www persistent rebalance slb-policy SVR-TO-SVR serverfarm WEB inservice !
VMware Trunk Port Group is supported from ACI version 2.1
VMM integration must be configured properly
ASA device package must be uploaded to APIC
ASAv version must be compatible with ACI and device package version
In the Previous articles of ACI Automation, we are using Postman/Newman as the Rest API tool to automate the ACI Configuration.
In this article I’m going to discuss on usin...
One of the first steps in building your ACI Fabric is to go through Fabric Discovery. While Fabric Discovery is usually a straightforward process, there are various issues that may prevent you from discovering an ACI switch. This article wil...