Prepare Your ACI Environment for Integration
Focus
Focus
VM-Series

Prepare Your ACI Environment for Integration

Table of Contents

Prepare Your ACI Environment for Integration

Set up your Cisco ACI environment to integrate the VM-Series firewall with a device package.
Where Can I Use This?What Do I Need?
  • Cisco ACI
  • VM-Series plugin
  • Panorama
  • VM-Series licenses
  • Cisco ACI Fabric
  • Panorama plugin for Cisco ACI
Before you can integrate the firewall with a device package, complete the following steps to prepare your Cisco ACI environment.
  1. Deploy the firewall:
    • Physical firewall—Connect the firewall’s out-of-band management port to one leaf switch port and connect at least one firewall data interface to the switch. Firewall interfaces on a physical firewall are configured with VLANs to ensure connectivity to the correct networks. Deploy the firewall according to the platform-specific installation guide.
    • VM-Series firewall—When configuring the virtual hardware for the VM-Series firewall, set the port-group for the management interface. Each VM-Series firewall connected to the network requires its own virtual NIC. Deploy the VM-Series firewall based on your hypervisor.
  2. Configure the management IP address on each firewall and Panorama:
    Perform initial configuration on:
  3. Add your firewall(s) to Panorama as a managed device.
  4. Install feature licenses on your firewalls:
  5. Establish Cisco ACI fabric and management connectivity:
    As part of this configuration, create a physical domain and VLAN namespace. Ensure that the data interfaces of any physical firewalls are part of the physical domain.
  6. Create a Cisco ACI VMM domain profile.
    If you are using virtual machines or the VM-Series firewall, create a virtual machine monitor (VMM) domain profile for the VMware vSphere environment. The VMM domain specifies the connectivity policy between the vSphere and the ACI fabric.