© Copyright Lenovo 2017
Chapter 16: VMready
291
VLAN Maps
A
VLAN
map
(VMAP)
is
a
type
of
Access
Control
List
(ACL)
that
is
applied
to
a
VLAN
or
VM
group
rather
than
to
a
switch
port
as
with
regular
ACLs
(see
).
In
a
virtualized
environment,
VMAPs
allow
you
to
create
traffic
filtering
and
metering
policies
that
are
associated
with
a
VM
group
VLAN,
allowing
filters
to
follow
VMs
as
they
migrate
between
hypervisors.
VMAPs
are
configured
using
the
following
ISCLI
configuration
command
path:
Enterprise
NOS
8.4
supports
up
to
128
VMAPs.
Individual
VMAP
filters
are
configured
in
the
same
fashion
as
regular
ACLs,
except
that
VLANs
cannot
be
specified
as
a
filtering
criteria
(unnecessary,
since
VMAPs
are
assigned
to
a
specific
VLAN
or
associated
with
a
VM
group
VLAN).
Once
a
VMAP
filter
is
created,
it
can
be
assigned
or
removed
using
the
following
commands:
For
regular
VLANs,
use
config
‐
vlan
mode:
For
a
VM
group,
use
the
global
configuration
mode:
Note:
Each
VMAP
can
be
assigned
to
only
one
VLAN
or
VM
group.
However,
each
VLAN
or
VM
group
may
have
multiple
VMAPs
assigned
to
it.
The
optional
intports
or
extports
parameter
can
be
specified
to
apply
the
action
(to
add
or
remove
the
VMAP)
for
either
the
internal
ports
or
external
ports
only.
If
omitted,
the
operation
will
be
applied
to
all
ports
in
the
associated
VLAN
or
VM
group.
Note:
VMAPs
have
a
lower
priority
than
port
‐
based
ACLs.
If
both
an
ACL
and
a
VMAP
match
a
particular
packet,
both
filter
actions
will
be
applied
as
long
as
there
is
no
conflict.
In
the
event
of
a
conflict,
the
port
ACL
will
take
priority,
though
switch
statistics
will
count
matches
for
both
the
ACL
and
VMAP.
CN 4093(config)#
access-control vmap
<VMAP
ID>
?
action Set filter action
egress-port Set to filter for packets egressing this port
ethernet Ethernet header options
ipv4 IP version 4 header options
meter ACL metering configuration
mirror Mirror options
packet-format Set to filter specific packet format types
re-mark ACL re-mark configuration
statistics Enable access control list statistics
tcp-udp TCP and UDP filtering options
CN 4093(config)#
vlan
<VLAN
ID>
CN 4093(config-vlan)#
[no] vmap
<VMAP
ID>
[intports| extports]
CN 4093(config)#
[no]
virt vmgroup
<ID>
vmap
<VMAP
ID>
[intports|extports]
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...