Match groups
Match groups allow you specify a profile for specific types of packets which can then be used to indicate their inclusion or exclusion from workload traffic.
In the Fabric Services System UI, you can:
- Create a match group.
- Edit a match group.
- Delete a match group.
Creating a match group
-
If you are not already on the Profiles page, do the
following:
- Click to open the main menu.
- Select Profiles.
- From the Profiles drop-down list, select Match Groups. The system displays the Match Groups page, showing a list of previously created match groups.
- To create an IPv4 or IPv6 match group, do one of the following:
- Click + CREATE IPV4 MATCH GROUP.
-
Enter general information about the match group:
- Enter a Name for the match group.
- Optional: Enter a Description.
-
Enter IPv4 match entry information for the match group:
Repeat this step until the IPv4 match entry list is complete.
- Do one of the following:
- Click + CREATE IPV6 MATCH GROUP. The Match Group Creation overlay displays.
- Enter general information about the match group:
- Enter a Name for the match group.
- Optional: Enter a Description.
-
Enter IPv6 match entry information for the match group:
The system closes the Match Group Creation overlay and returns you to the Profiles page with the Match Group view selected. The match group you just created is now included in the list of available match groups.
- You have completed this procedure.
Editing a match group
After you edit a match group, you must update ACLs that rely on that match group. To aid you in identifying the affected ACLs, these ACLs display a True flag in their Need update status. Open and save the ACL.
If the updated ACL profile is being used by a workload VPN intent, and that workload VPN intent has already been generated or deployed, then you must regenerate that workload VPN intent:
- If the workload VPN intent has been generated but is not yet deployed, you can re-save and regenerate the workload VPN intent without creating a new version. Regenerating the workload VPN intent incorporates the new ACL settings into its configuration.
- If the workload VPN intent has already been deployed, you need to create a new candidate version of the workload VPN intent before you can regenerate and redeploy it with the new ACL settings.
-
If you are not already on the Profiles page, do the
following:
- Click to open the main menu.
- Select Profiles.
- From the Profiles drop-down list, select Match Groups. The system displays the Match Groups page, showing a list of previously created match groups.
- Select a match group from the list, click the More actions icon ( ) at the right edge of the row, and select Open from the drop-down list.
- Update parameters for the match group.
- At the lower right of the Match Groups overlay, click SAVE.
Deleting a match group
To delete a match group:
-
If you are not already on the Profiles page, do
the following:
- Click to open the main menu.
- Select Profiles.
- In the Profiles drop-down list, click Match Groups.
- Select a match group from the list by clicking on the More actions icon ( ) at the right edge of the row, and select Delete from the drop-down list.
-
In the confirmation form, click OK.
The system deletes the selected match group and closes the confirmation form, returning you to the Profiles page with the Match Groups view selected. The match group you just deleted no longer appears in the list.