Appendix: Workload VPN intent parameters
This appendix describes the workload intent parameters in the Fabric Services System.
Workload intent
Basic parameters (workload intent) and Subnet parameters (workload intent) define the required and optional workload intent parameters and the appropriate values that can be inputted in the platform.
Parameter |
Description |
Values/Range |
---|---|---|
Workload VPN Intent Name |
A unique name you assign to the workload VPN intent. |
Any string value |
Description |
A description you provide for the workload VPN intent. |
Any string value |
Fabric Intents |
Use this field to select one or more fabrics whose resources should participate in the workload intent. |
By Fabric |
Labels |
Although not enabled during workload intent creation, this field can be used later to apply labels to the workload intent itself. |
Supported labels |
Parameter |
Description |
Values |
---|---|---|
Name |
A name you assign to the subnet. |
Any string value |
Description |
A description you provide for the subnet. |
Any string value |
Type |
Select a supported subnet type from the drop-down list. |
Bridged Routed |
IP Anycast Gateway (V4/V6) |
For bridged subnets, an IP gateway to act as an IRB interface. |
Enter a valid IPv4 or IPv6 address with a required CIDR. |
IPv4 Learn Unsolicited ARP Enabled | For IPv4 addresses within the subnet, setting this to True enables the learning of ARP entries out of any ARP packet arriving at the IRB sub-interface, regardless of whether there was an ARP-Request issued from the IRB. | True, False |
IPv6 Learn Unsolicited ARP Enabled | For IPv6 addresses within the subnet, setting this to True enables the learning of Neighbor Discovery Request entries out of any Neighbor Discovery Request packet arriving at the IRB sub-interface, regardless of whether there was an Neighbor Discovery Request issued from the IRB. | True, False |
ACL Profile |
For bridged subnets, an Access Control list that will restrict the traffic permitted to cross the subnet. |
Select an already-configured ACL profile |
IP MTU |
For bridged subnets, the maximum transmission unit allowed. |
1500+ |
Parameter |
Description |
Values |
---|---|---|
Description |
A description you provide for the selected sub-interface. |
Any string value |
VLAN ID |
The VLAN ID associated with the current sub-interface. |
Specify an available VLAN ID (1+) |
ACL Profile |
An Access Control List that defines the traffic that is permitted (and by implication, excluded) on the sub-interface. |
Select an already-defined ACL profile. |
Workload specific ACL optimization |
Setting this value to On causes the system to verify that the selected ACL profile’s IP address range is contained within the set of Gateway IP addresses you enter for this sub-interface. |
On, Off |
IP MTU |
The Maximum Transmission Unit for the sub-interface; this is the maximum size for an IP packet that will not be fragmented in the course of transmission. |
1500+ |
Association parameters |
||
Subnet |
The subnet with which this sub-interface is associated. |
Select an existing subnet from the drop-down list. |
Association Type |
The method used to associate this sub-interface with its "parent" subnet. |
Currently fixed as "Node and Interface" |
Node ID |
The node within the fabric on which the current sub-interface is located. |
Select an existing leaf node within the fabric or fabrics associated with this workload VPN intent. |
Interface Name |
The specific interface on the selected node with which this sub-interface is associated. This can be a LAG. |
Select an interface from the drop-down list. |
IP Gateway (V4/V6) |
IP address of the forwarding device. | Enter the IP address of the gateway device. |
QoS parameters |
||
QoS Classifier (IP V4) |
Quality-of-Service classifier (DSCP value and forwarding class) for an IPv4 address. |
Select an already-defined QoS profile from the drop-down list. |
QoS Classifier (IP V6) |
Quality-of-Service classifier (DSCP value and forwarding class) for an IPv6 address. |
Select an already-defined QoS profile from the drop-down list. |
QoS Rewrite Rules (IP V4) |
Quality-of-Service rewrite rules (forwarding class and DSCP selection) for an IPv4 address. |
Select an already-defined QoS profile from the drop-down list. |
QoS Rewrite Rules (IP V6) |
Quality-of-Service rewrite rules (forwarding class and DSCP selection) for an IPv6 address. |
Select an already-defined QoS profile from the drop-down list. |