Monday, November 25, 2019

Cisco UCS - Fabric Interconnects - VLAN communication - How is this happening?

I have more of an informational/fuctional question.

I am currently not understanding exactly how our UCS system is passing VLAN traffic to our VMware servers and beyond. I was tasked with adding an additional couple VLANs to the FI's in UCS Manager for some new networks that will be for new servers in vmware.

We currently have a redundant UCS system. 2x chassis, 2x Fab A, 2x Fab B. Cisco 6300 Fabric Interconnects. vmware vSphere running on top. The redundant systems are split across the property as our Cold Room (CR) and Disaster Recovery (DR) areas. If CR explodes then DR should take over and vice versa.

From what I am gathering I need to add the VLANS into UCS Manager through the LAN Uplinks Manager -> Vlan Manager. Then apply those new VLANS onto the VNIC template for the ESXI hosts.

My confusion starts here:

UCS Manager CR Site:

We have all the VLANS added into a VLAN Group. This VLAN group is carrying production vlans and is attached to the VNIC template in UCS Manager. I am also seeing this VLAN group attached to the port-channel used for FAB-A and FAB-B. I am guessing I need to add my needed VLANS to this group to complete my task for the CR side? Will this cause any temporary network vnic issues during the add?

UCS Manager DR Site:

This is set up similar to the CR site but the VLAN group here does not have any port-channels attached to it, but this VLAN Group is apart of the VNIC templates for ESXI Hosts. I am unable to edit said VLAN Group. I would say permissions issue, but even the admin account the vendor used to set this up with doesnt allow me to add additional vlans to the group. I can see my new VLAN added into the general pool but I am unable to place it anywhere.

It concerns me to see that the DR site does not have a port-channel attached to the VLAN group and makes me wonder how this is functioning? Does the UCS Manager system just accept and add any new VLAN added? I was under the impression adding a new VLAN here without an associated uplink or port-channel is a massive no no?



No comments:

Post a Comment