Beruflich Dokumente
Kultur Dokumente
2x1 GE
CIMC 1 GE
Cisco UCS E-Series server
Network options to steer VM traffic
Cisco IOS/IOS-XE
CIMC CLI/GUI
Note: A double-wide UCS E-series server will have a fourth interface labeled ge3. This is an external
facing interface that maps to vmnic3 on the virtual network side
• The backplane network interfaces can be monitored via installed OS and router monitoring features
• The backplane interfaces support router BDI, sub-interface, VLAN and SVI and other IOS/IOS-XE features
• The external front-facing network interfaces are only accessible by the server and can only be monitored by the installed OS
• On a double-wide server you can configure NIC teaming using the two front-facing interfaces to create redundancy or increase bandwidth
Service Chaining Applications
To WAN Ingress WAN traffic from the ISR WAN port is
1
redirected to vWAAS running on the UCS®-E
Motherboard
2 vWAAS will redirect traffic back to the ISR router
3
WCCP IN
UCSE1/0/0 UCS-E1/0/1
(BDI 10) (BDI 20) Use standard routing to route traffic from vWAAS to
3
BDI/VLAN 20 to the UCS-E blade
1 2 4
GE 0 GE 1
Traffic will be routed to the vASA outside interface set
4
to its own internal switch
vNIC
vSwitch0 vSwitch1 vSwitch2 vWSA
Traffic is filtered and only authorized traffic is allowed
ESX Host
vmnic2
6 5
out to the vASA inside network
vNIC
vWAAS vASA 7 vWLC
vWSA and miscellaneous LAN apps are installed
6 behind the firewall so they are accessible to
LAN devices
GE 2
vWAAS
Configuration Example: vWAAS + vNGIPS
LAN access sw
10.0.1.0 /16 WAN
Intfc GE 0/0/0
desription WAN intfc
vWAAS
Using IP SLA and EEM script to provide Fail-
Open backup if IPS service fails
• IP SLA continuously monitors connection across FirePower
• If connectivity fails the EEM script configures the LAN facing router GE
interface into the “global route table” and send a “fail” email notification
• During IPS failure LAN devices can still reach the outside, but have no
IPS/IDS protection
• Once the IPS is back online the IP SLA ping will be successful and activate
a second EEM script
• The second EEM script will reconfigure the LAN facing router GE interface
back to the “vrf inside” to force traffic across FirePower
Cisco IP SLA ping and EEM script Reference
IP SLA ping config: IPS down EEM script config:
event manager environment _email_to your-to-mail@domain.com
track 1 ip sla 1 event manager environment _email_server your.mail.server
delay down 3 event manager environment _email_from your-from-mail@domain.com
! !
ip sla 1 event manager applet ipsla_ping-down
icmp-echo 192.168.24.1 source-ip 192.168.24.2 event syslog pattern "1 ip sla 1 state Up -> Down"
vrf inside action 1.0 cli command "enable"
threshold 500 action 1.5 cli command "config term"
timeout 1000 action 2.0 cli command "interface g0/0/2"
frequency 2 action 2.5 cli command "no ip vrf forwarding"
ip sla schedule 1 life forever start-time now action 2.6 cli command "ip address 192.168.25.1 255.255.255.0"
! action 2.7 cli command "ip nat inside"
end action 2.8 cli command "ip wccp 61 redirect in"
action 3.0 cli command "end"
IPS up EEM script config: action 3.1 cli command "wr mem“
event manager applet ipsla_ping-up action 4.0 mail server "$_email_server" to "$_email_to" from "$_email_from" subject
"$_event_pub_time: IPS down!" body "$_syslog_msg"
event syslog pattern "1 ip sla 1 state Down -> Up " action 4.1 syslog priority notifications msg "priority" facility "state Up -> Down - Mail Sent"
action 1.0 cli command "enable"
action 1.5 cli command "config term"
action 2.0 cli command "interface g0/0/2"
action 2.5 cli command "ip vrf forwarding inside"
action 2.6 cli command "ip address 192.168.25.1 255.255.255.0"
action 2.7 cli command "no ip nat inside"
action 2.8 cli command "no ip wccp 61 redirect in"
action 3.0 cli command "end"
action 3.1 cli command "wr mem"
Server Performance
vWAAS and FirePower Tests
UCSE 140S-M2 LAN WAN Router DP UCS-E
(Mbps) (Mbps) CPU% CPU%
Example: vWAAS test
182 Mbit/s 128 Mbit/s
No Service 1200 1180 12 n/a
ISR4451
vWAAS 617 308 29 97 LAN 2 Gbit/s
WAN
FirePower (IDS) 648 600 98 96 435 Mbit/s 180 Mbit/s
vWAAS + FirePower (IDS) 365 190 89 100
Requires a 2 server cluster, centralized vCenter can act as tiebreaker between two out-of-sync servers
Uses direct-attached HDDs/SSDs to create a shared storage iSCSI target
Virtual machine files (.vmdk, .vmx, .nvram, etc..) are mirrored across servers
Leverage UCS E-series backplane interfaces to connect management, mirroring and iSCSI network traffic
If one server fails the VMs survive running on the available server
When the failed server is recovered, SvSANs communicates with the neutral storage host to determine which host
contains the most up-to-date data, and begin to re-synchronize
Cisco UCS E-series application survivability
Box-to-Box Redundancy
mgmt mgmt
ESXi ESXi
UCS-E UCS-E
SSD caching
Current version is a “write back” cache
VM
• Improves overall I/O write performance significantly
• Delivers low latency access improving application response times 1. Data written directly to 2. Write acknowledged,
• Reduces the number of I/Os going directly to disk cache data in cache is “dirty”
In ROBO environments the amount of data written per day is relatively low
• Ranging from a few tens of Gigabytes to hundreds of Gigabytes
• A 250GB SSD could cache a days worth of data