22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

LinkSec encryption on all M-series <strong>and</strong> some F2e-series interfaces in hardware. Refer to<br />

Figure 5-8 if you have a Multiprotocol Label Switching (MPLS) environment; you can frontend<br />

the Nexus 7000 switches with an ASR1000 or a Catalyst 6500 running port-mode<br />

Ethernet over MPLS (EoMPLS). Port-mode EoMPLS looks like a wire to the Nexus 7000;<br />

this is important because you need to make sure that the control-plane SAP messages<br />

(Security Association Protocol EAPOL frames) for CTS Encryption are forwarded through<br />

the EoMPLS pseudo-wire (PW). Also, Virtual port-channel (vPC) on the Nexus 7000<br />

enables for a loop-free spanning-tree environment <strong>and</strong> STP isolation so that you can have an<br />

STP root in each data center.<br />

If MPLS is not required, the Nexus 7000 TrustSec can secure data acr<strong>os</strong>s a remote data<br />

center if Layer 2 <strong>and</strong> BPDU transparency is ensured through dark fiber or dense wavelength<br />

division multiplexing (DWDM) transport.<br />

If the Cisco ASR1000 is used for the port-mode EoMPLS connectivity, it provides remoteport<br />

shutdown where communication of link status to a CE <strong>and</strong> traffic from the Customer<br />

Edge (CE) can be stopped if MPLS or the PW is down. Remote port shutdown enables<br />

subsecond failover <strong>and</strong> restoration to local/remote links/nodes end-to-end signaled through<br />

LDP.<br />

Figure 5-22 illustrates Data Center Interconnect, which provides P2P interconnect with<br />

encryption through the MPLS cloud. The Nexus 7000s <strong>and</strong> ASR1002s are configured with<br />

Cisco TrustSec <strong>and</strong> port-mode EoMPLS PW, respectively.<br />

Figure 5-22. Data Center Interconnects Acr<strong>os</strong>s an MPLS Cloud Leveraging Cisco<br />

TrustSec on the Nexus 7000<br />

Configuring IP ACLs<br />

ACLs are ordered sets of rules that you can use to filter traffic; each rule specifies a set of<br />

conditions that a packet must satisfy to match the rule. The first matching rule determines<br />

whether the packet is permitted or denied. ACLs protect networks <strong>and</strong> specific h<strong>os</strong>ts from<br />

unnecessary or unwanted traffic. NX-OS supports IPv4 <strong>and</strong> IPv6 IP ACLs to be created <strong>and</strong><br />

applied to interfaces, VLAN interfaces, <strong>and</strong> port-channels.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!