End-of-Life (EoL)

Create an L4-L7 Service

Now that you have created your tenant with an application profile containing two EPGs, you must configure the firewall as a L4-L7 Service and insert that service between the EPGs. The firewall service then secures the traffic between the EPGs.
  1. Enter general information about the firewall.
    1. Right click
      L4-L7 Devices
      and select
      Create L4-L7 Devices
      .
    2. Enter a
      Name
      for your firewall service.
    3. Select
      Firewall
      from the Service Type drop-down.
    4. Under Device Type, select
      Physical
      or
      Virtual
      depending on the firewall you deployed.
    5. Select the Physical or VMM Domain. This is the same domain you chose when creating the application profile.
    6. Under View, select Single Node for a single firewall or HA Node for firewalls in an HA pair.
    7. Select the Device Package.
    8. Select the Model of the firewall you deployed. The device package comes preset with several Palo Alto Networks firewall models.
    9. Set
      Context Aware
      to
      Multiple
      for multi-vsys deployments.
    10. Under Function Type, select GoThrough for L2 and GoTo for L3.
    11. Choose a connectivity mode for the APIC to device management connection. This setting defines how Cisco APIC connects to the firewall and to Panorama management interfaces. Choose the setting most appropriate for your environment. If the management interfaces if the firewall and Panorama have nit been added to an EPG, then you would typically choose
      Out-Of-Band
      . Out-Of-Band management is recommended.
    12. Enter the login credentials for the firewall.
    create_L4L7_device1.png
  2. Configure device 1 (the firewall).
    1. Enter the firewall management IP address and select HTTPS as the management port.
    2. (VM-Series only) Under VM, select the VM-Series firewall you deployed. All virtual machines connected to the ACI fabric are listed here.
    3. (Physical firewall only) Select a Chassis. This directs the firewall to create a new vsys and apply the configuration from the APIC there. Without a chassis select, APIC applies its network configuration to vsys1 and potentially overrides any configuration that already exists on vsys1.
    4. Click the plues (+) icon under Device Interfaces to add your interfaces.
      For the VM-Series firewall, select ethernet 1/1 as the first data port and Network adapter 2 as the vNIC. vNIC network adapter 1 is reserved for the firewall management port.
    5. For physical firewalls, in addition to select the ethernet port, you must also specify a path. The path is the physical port on a leaf switch that the firewall is connected to. This mapping was determined when you created you ACI Fabric and deployed your firewall.
    create_device.png
  3. Configure the cluster. A cluster is a group of up to two identically configure L4 to L7 devices. The firewall(s) within the cluster are called concrete devices.
    1. Enter the Management IP Address. This is the same IP address as device 1.
    2. Set the Management Port to HTTPS.
    3. Set the Device Manager to Panorama.
    4. Set the Cluster Interfaces. The cluster interfaces define which side of the firewall and which side is external.
      1. Set the Type of the first interface to consumer (typically external) and give it a
        Name
        .
      2. Set a Concrete Interface from the drop-down. You defined the interfaces on the list when you configured in the interfaces for device 1.
      3. Set the Type of the second interface to provider (typically internal) and give it a
        Name
        .
      4. Select a Concrete Interface from the drop-down.
    5. Click
      Next
      to proceed to the Basic parameters tab.
    create_cluster.png
  4. Configure basic parameters of the firewall. In a single, non-HA firewall deployment, only the Basic Parameters under Device Settings are required.
    1. Expand the
      Device Settings
      folder.
    2. Click
      DNS Server (primary)
      and enter a Name in the Name column and an IP address in the Value column.
    3. Click
      Update
      .
    4. Click
      Firewall Hostname
      and enter a hostname in the Value column. APIC automatically populates the Name column with
      hostname
      .
    5. Click
      Update
      .
    6. Click
      Finish
      .
    The parameters under All Parameters are optional.
  5. Verify that your L4-L7 Device was deployed successfully.
    1. Select
      Tenants
      <your-tenant>
      L4-L7 Services
      L4-L7 Devices
      and select the cluster you created.
    2. Under Configuration State, the Device State proceeds through several states including
      init
      ,
      verificationPending
      ,
      auditPending
      , and finally
      stable
      .
      If the Device State does not reach stable state or shows any state not listed above, select
      Faults
      to determine the problem and follow the presented directions to resolve the problem.

Recommended For You