22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Example 9-31 shows the security policy that was created in VNMC was successfully pushed<br />

to the Cisco VSG Firewall running on the Nexus 1010 VSB.<br />

The following steps show how to configure <strong>and</strong> verify the policy-agent for the Cisco VSG<br />

<strong>and</strong> VSM Communication.<br />

Example 9-31. Verify the Policy-Agent Is Copied to the VSG bootflash<br />

Click here to view code image<br />

vsg# dir<br />

20053444 Aug 22 15:09:06 2012 vnmcvsgpa.1.3.1d.bin<br />

Example 9-32 shows how to create the port-profiles on the Nexus 1000v VSM for the VSG<br />

policy enforcement. The port-profile enables the VM Traffic for the Firewall Policy. vPath<br />

on the installed VEM performs this functionality. The port-profile will be assigned to the<br />

virtual machine.<br />

Example 9-32. Port-profile Enables the VM Traffic for the Firewall Policy<br />

Click here to view code image<br />

vsm# conf t<br />

Enter configuration comm<strong>and</strong>s, one per line. End with<br />

CNTL/Z.<br />

vsm(config)# port-profile VLAN104<br />

vsm(config-port-prof)# vn-service ip-address 10.104.0.200<br />

vlan 104 security-profile<br />

Employee<br />

vsm(config-port-prof)# org root/Employee<br />

vsm(config-port-prof)# show runn port-profile VLAN104<br />

!Comm<strong>and</strong>: show running-config port-profile VLAN104<br />

!Time: Sun Aug 26 20:47:03 2012<br />

version 4.2(1)SV1(5.1a)<br />

port-profile type vethernet VLAN104<br />

vmware port-group<br />

switchport mode access<br />

switchport access vlan 104<br />

org root/Employees<br />

no shutdown<br />

vn-service ip-address 10.104.0.200 vlan 104 security-

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!