Sunteți pe pagina 1din 7

You need create manually vCenter integration and ASAv and SGT.

no mcp action
vlan-domain DC1-L3DOM type l3ext
vlan-pool VLAN_POOL
vlan 10-20
exit
template port-channel UCS_FI_A_VPC
no description
lldp receive
lldp transmit
no cdp enable
switchport port-security maximum 0
switchport port-security violation protect
switchport port-security timeout 60
switchport mode f
channel-mode on
lacp min-links 1
lacp max-links 16
no lacp symmetric-hash
mcp enable
spanning-tree bpdu-filter disable
spanning-tree bpdu-guard disable
speed auto
negotiate auto
link debounce time 100
storm-control level 100.00 burst-rate 100.00
storm-control pps 100 burst-rate 100
slow-drain pause timeout 500
slow-drain congestion-timeout count 10
slow-drain congestion-timeout action err-disable
priority-flow-control mode auto
no inherit macsec interface-policy
exit
template port-channel UCS_FI_B_VPC
no description
lldp receive
lldp transmit
no cdp enable
switchport port-security maximum 0
switchport port-security violation protect
switchport port-security timeout 60
switchport mode f
channel-mode on
lacp min-links 1
lacp max-links 16
no lacp symmetric-hash
mcp enable
spanning-tree bpdu-filter disable
spanning-tree bpdu-guard disable
speed auto
negotiate auto
link debounce time 100
storm-control level 100.00 burst-rate 100.00
storm-control pps 100 burst-rate 100
slow-drain pause timeout 500
slow-drain congestion-timeout count 10
slow-drain congestion-timeout action err-disable
priority-flow-control mode auto
no inherit macsec interface-policy
exit
vlan-domain CCIE-DVS dynamic type vmware
vlan-pool vCenter_Pool
vlan 10-20 dynamic
exit
vmware-domain CCIE-DVS access-mode readwrite
vlan-domain member CCIE-DVS type vmware
vcenter "IP address of vCenter" datacenter "Name_Datacenter"
username "user@domain"
exit
configure-dvs
exit
ep-retention-time 0
exit
tenant common
application Span
epg span
bridge-domain member default
set qos-class unspecified
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
set qos-class unspecified
exit
exit
tenant core
access-list appToDBFilter
match icmp
match tcp dest 443
match tcp dest 80
exit
contract ApptoDB
set qos-class unspecified
set target-dscp unspecified
scope vrf
subject SBJ
set qos-class unspecified
set target-dscp unspecified
label match provider any
label match consumer any
l4l7 graph AppToDB
reverse-port
exit
exit
contract DC1-to-DC2
set qos-class unspecified
set target-dscp unspecified
scope vrf
exit
vrf context vrf1
contract enforce ingress
no whitelist-blacklist-mix
exit
l3out DC1
vrf member vrf1
ip pim
route-control export
exit
l3out DC2
vrf member vrf1
ip pim
route-control export
exit
bridge-domain bd-inside
no arp flooding
no endpoint move-detection
enforce-subnet-learning
no ep-flush
no fc
ip learning
l2-unknown-unicast proxy
l3-unknown-multicast opt-flood
multi-destination encap-flood
unicast routing
vrf member vrf1
exit
bridge-domain bd_outside
no arp flooding
no endpoint move-detection
enforce-subnet-learning
no ep-flush
no fc
ip learning
l2-unknown-unicast proxy
l3-unknown-multicast opt-flood
multi-destination encap-flood
no unicast routing
vrf member vrf1
exit
application App
epg app
bridge-domain member bd_outside
contract consumer ApptoDB qos-class unspecified
set qos-class unspecified
vmware-domain member CCIE-DVS encap auto primary-encap auto deploy
immediate push immediate
switching-mode native
encap-mode auto
no cos enable
security allow-promiscuous accept
security mac-changes accept
security forged-transmits accept
no flow monitor enable
flow direction both
exit
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
epg backup
bridge-domain member bd-inside
set qos-class unspecified
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
epg database
bridge-domain member bd-inside
contract provider ApptoDB qos-class unspecified
set qos-class unspecified
vmware-domain member CCIE-DVS encap auto primary-encap auto deploy
immediate push immediate
switching-mode native
encap-mode auto
no cos enable
security allow-promiscuous accept
security mac-changes accept
security forged-transmits accept
no flow monitor enable
flow direction both
exit
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
epg dhcp-server
bridge-domain member bd_outside
set qos-class unspecified
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
set qos-class unspecified
exit
external-l3 epg DC1 l3out DC1
vrf member vrf1
set dscp unspecified
set qos-class unspecified
no deny-mode
exit
external-l3 epg DC2 l3out DC2
vrf member vrf1
set dscp unspecified
set qos-class unspecified
no deny-mode
exit
interface bridge-domain bd-inside
no ip multicast
ipv6 link-local ::
mac-address 00:22:BD:F8:19:FF
no multi-site-mac-address
exit
interface bridge-domain bd_outside
ip address 172.16.3.254/24 secondary scope private
no ip multicast
ipv6 link-local ::
mac-address 00:22:BD:F8:19:FF
no multi-site-mac-address
exit
l4l7 cluster name ASAv type virtual vlan-domain CCIE-DVS switching-mode native
service FW function go-through context single trunking disable
cluster-device Device1 vcenter vCenter vm "asav-vi"
cluster-interface inside
member device Device1 device-interface GigabitEthernet0/0
vnic "Network adapter 2"
exit
exit
cluster-interface outside
member device Device1 device-interface GigabitEthernet0/1
vnic "Network adapter 3"
exit
exit
exit
exit
tenant mgmt
oob-mgmt epg default
contract provider default
exit
contract default type oob-mgmt
set qos-class unspecified
set target-dscp unspecified
scope vrf
subject default
set qos-class unspecified
set target-dscp unspecified
label match provider any
label match consumer any
reverse-port
exit
exit
exit
leaf-profile Leaf-101
description 'GUI Interface Selector Generated Profile: Leaf-101'
leaf-group Leaf-101_selector_101
no description
leaf 101
leaf-policy-group Leaf-SPG
exit
leaf-interface-profile leaf-101
exit
leaf-profile Leaf-102
description 'GUI Interface Selector Generated Profile: Leaf-102'
leaf-group Leaf-102_selector_102
no description
leaf 102
leaf-policy-group Leaf-SPG
exit
leaf-interface-profile leaf-102
exit
leaf-interface-profile leaf-102
no description
leaf-interface-group UCS_FI_B
no description
interface ethernet 1/24
channel-group UCS_FI_B_VPC vpc
exit
exit
vpc domain explicit 1 leaf 101 102
peer-dead-interval 200
exit
tenant TN-A
vrf context VRF_A
contract enforce ingress
no whitelist-blacklist-mix
exit
vrf context VRF_B
contract enforce ingress
no whitelist-blacklist-mix
exit
bridge-domain BD_A
arp flooding
no endpoint move-detection
no enforce-subnet-learning
no ep-flush
no fc
ip learning
l2-unknown-unicast flood
l3-unknown-multicast flood
multi-destination bd-flood
no unicast routing
vrf member VRF_A
exit
bridge-domain BD_B
arp flooding
no endpoint move-detection
no enforce-subnet-learning
no ep-flush
no fc
ip learning
l2-unknown-unicast flood
l3-unknown-multicast flood
multi-destination bd-flood
unicast routing
vrf member VRF_B
exit
application app_a
epg EPG_A
bridge-domain member BD_A
set qos-class unspecified
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
epg EPG_B
bridge-domain member default
set qos-class unspecified
no isolation enforce
no vrf-blacklist-mode
no flood-on-encapsulation
exit
set qos-class unspecified
exit
interface bridge-domain BD_A
no ip multicast
ipv6 link-local ::
mac-address 00:22:BD:F8:19:FF
no multi-site-mac-address
exit
interface bridge-domain BD_B
no ip multicast
ipv6 link-local ::
mac-address 00:22:BD:F8:19:FF
no multi-site-mac-address
exit
exit

S-ar putea să vă placă și