on 28-Dec-2015 08:09
The adoption of Cisco ACI with the APIC controller continue to gain traction in the market. With their latest major APIC release, 1.2.1i , Cisco has streamlined how ADCs are connected to the fabric. There have traditionally been two methods of connecting services:
What Cisco has done is simplified how a services device can be connected into the fabric as an Unmanaged device to the APIC. This is known as “Unmanaged Mode” vs the “Managed Mode” where a device package is used.
Instead of the usual multi-step manual configuration process for specifying the network configuration in APIC, the attachment has been consolidated into the service graph. Before it was necessary to manually static bind the VLAN to the EPG (Provider and Consumer) and assign the physical domain to the EPG. It was also required to bind contracts between multiple Provider and Consumer EPGs. Now, all you have to do is go into the service graph and specify connectivity just like you were building a managed service graph. By doing this, there is now one common location and workflow for configuring services. The process is simplified.
Advantages
Why needed
What this means for BIG-IP integration
Difference between Managed and Unmanaged mode
Mode |
Goal |
Unmanaged Mode |
|
Managed Mode |
|
Some prerequisites for deploying an Unmanaged logical device cluster
Click here to view a video with more details on how to deploy a BIGIP in Unmanaged mode on APIC
https://www.youtube.com/watch?v=OJPEYzNGD3A
Once deployed as an Unmanaged device cluster with traffic redirection through ACI configure your BIGIP with nodes, pools, monitors, virtual servers and all other features required by your application like you always do by using the BIG-IP GUI/CLI etc (not through the Cisco ACI)
References:
http://blogs.cisco.com/datacenter/new-innovations-for-l4-7-network-services-integration-with-ciscos-aci-approach
Hi Payal,
Thanks for this informative article. I have couple of queries,
If I am integrating F5 in unmanaged mode then do I need to create a tenant for same in Cisco ACI. How my traffic will land to F5 guest as this is not a full integration then how can I map my F5 guest with ACI.
/Regards
Amit Grover
hi Payal, is there a guide available to deploy F5 in One-arm. Currently we are planning to attach F5 with ACI in one arm mode. The idea would to use SNAT poll to do Health check and for data communication with end servers as well. We will have F5-OUT-EPG and F5-IN-EPG attached to a single interface in one-arm. Subnet would be something like this