Appendix: Workload VPN intent parameters

This appendix describes the workload intent parameters in the Fabric Services System.

Workload intent

Basic parameters (workload intent) and Subnet parameters (workload intent) define the required and optional workload intent parameters and the appropriate values that can be inputted in the platform.

Table 1. Basic parameters (workload intent)

Parameter

Description

Values/Range

Workload VPN Intent Name

A unique name you assign to the workload VPN intent.

Any string value

Description

A description you provide for the workload VPN intent.

Any string value

Fabric Intents

Use this field to select one or more fabrics whose resources should participate in the workload intent.

By Fabric

Labels

Although not enabled during workload intent creation, this field can be used later to apply labels to the workload intent itself.

Supported labels

Table 2. Subnet parameters (workload intent)

Parameter

Description

Values

Name

A name you assign to the subnet.

Any string value

Description

A description you provide for the subnet.

Any string value

Type

Select a supported subnet type from the drop-down list.

Bridged

Routed

IP Anycast Gateway (V4/V6)

For bridged subnets, an IP gateway to act as an IRB interface.

Enter a valid IPv4 or IPv6 address with a required CIDR.

IPv4 Learn Unsolicited ARP Enabled For IPv4 addresses within the subnet, setting this to True enables the learning of ARP entries out of any ARP packet arriving at the IRB sub-interface, regardless of whether there was an ARP-Request issued from the IRB. True, False
IPv6 Learn Unsolicited ARP Enabled For IPv6 addresses within the subnet, setting this to True enables the learning of Neighbor Discovery Request entries out of any Neighbor Discovery Request packet arriving at the IRB sub-interface, regardless of whether there was an Neighbor Discovery Request issued from the IRB. True, False

ACL Profile

For bridged subnets, an Access Control list that will restrict the traffic permitted to cross the subnet.

Select an already-configured ACL profile

IP MTU

For bridged subnets, the maximum transmission unit allowed.

1500+

Table 3. Sub-interface parameters (workload intent)

Parameter

Description

Values

Description

A description you provide for the selected sub-interface.

Any string value

VLAN ID

The VLAN ID associated with the current sub-interface.

Specify an available VLAN ID (1+)

ACL Profile

An Access Control List that defines the traffic that is permitted (and by implication, excluded) on the sub-interface.

Select an already-defined ACL profile.

Workload specific ACL optimization

Setting this value to On causes the system to verify that the selected ACL profile’s IP address range is contained within the set of Gateway IP addresses you enter for this sub-interface.

On, Off

IP MTU

The Maximum Transmission Unit for the sub-interface; this is the maximum size for an IP packet that will not be fragmented in the course of transmission.

1500+

Association parameters

Subnet

The subnet with which this sub-interface is associated.

Select an existing subnet from the drop-down list.

Association Type

The method used to associate this sub-interface with its "parent" subnet.

Currently fixed as "Node and Interface"

Node ID

The node within the fabric on which the current sub-interface is located.

Select an existing leaf node within the fabric or fabrics associated with this workload VPN intent.

Interface Name

The specific interface on the selected node with which this sub-interface is associated. This can be a LAG.

Select an interface from the drop-down list.

IP Gateway (V4/V6)

IP address of the forwarding device. Enter the IP address of the gateway device.

QoS parameters

QoS Classifier (IP V4)

Quality-of-Service classifier (DSCP value and forwarding class) for an IPv4 address.

Select an already-defined QoS profile from the drop-down list.

QoS Classifier (IP V6)

Quality-of-Service classifier (DSCP value and forwarding class) for an IPv6 address.

Select an already-defined QoS profile from the drop-down list.

QoS Rewrite Rules (IP V4)

Quality-of-Service rewrite rules (forwarding class and DSCP selection) for an IPv4 address.

Select an already-defined QoS profile from the drop-down list.

QoS Rewrite Rules (IP V6)

Quality-of-Service rewrite rules (forwarding class and DSCP selection) for an IPv6 address.

Select an already-defined QoS profile from the drop-down list.