ExtremeCloud Orchestrator CLI Administration Guide Version 3.2.0.
> Policy Service Provisioning
Published March 2023
Search this document
Print this page
Email this page
View PDF
Previous
Next
Preface
Text Conventions
Documentation and Training
Help and Support
Send Feedback
What's New in this Document
Introduction to ExtremeCloud Orchestrator
Evolution of EFA and XVM into XCO
Fabric Automation and Orchestration
Visibility Solution
XCO Microservices
REST API Documentation for XCO
XCO System Management
Verify the Running System and Services
Log in to XCO
XCO Certificate Management
Device Certificates
Syslog CA
OAuth Certificate
HTTPS Certificates
Manual Installation of Certificates on Devices
XCO Certificates
XCO Root CA
XCO Intermediate CA
XCO Server Certificate
JWT Certificate
K3s CA
K3s Server Certificate
Host Authentication Certificate
External Certificates
Certificate Troubleshooting
Monitoring XCO Status
Verifying XCO System Health
XCO System Backup and Restoration
Back up and Restore the XCO System
Change the Host Name or IP Address
Display XCO Running Configurations
Audit Trail Logging
Transfer of Audit Trail Data
Logging and Log Files
Logging Customization
Configure Logging
Unconfigure Logging
Data Consistency
Periodic Device Discovery
Persistent Configuration
Drift and Reconcile
Network Elements
Idempotent Operations
Rollback Scenarios for Data Consistency
XCO High Availability Failover Scenarios
Multiple Management IP Networks
Add and Delete Management Routes
Configuration Supporting Multiple Management IP Networks
Add and Delete Management Subinterfaces
Configure Static IP Addresses for Management Sub interfaces
Change the Default Gateway of a TPVM
Northbound IPv6 support
Configure DNS Nameserver Access
Change Password of efainternal User
Accessing Supportsave without Login
Linux Exit Codes
Linux Error Exit Code
Fabric Infrastructure Provisioning
Fabric Service Overview
IP Fabric and Clos Orchestration Overview
SLX Device Prerequisites for Fabric Service
Configure Hardware Profile to Limit IPv6 Prefix to 64
Clos Overview
Configure a 3-Stage Clos Fabric
Configure a 5-Stage Clos Fabric
Provisioning Model to Migrate a 3-Stage Clos to 5-Stage Clos Fabric
Migrate a 3-Stage Clos to 5-Stage Clos Fabric
Create a 3-Stage Clos Fabric
Migrate a 3-Stage Clos to 5-Stage Clos Fabric
Disconnect Border-leafs from Spine and Connect to Super-spine
Addition of Super-spine Devices to the Migrated 5-stage Clos Fabric
Configure the Migrated 5-stage Clos Fabric
Traffic Disruption during Fabric Configure
Verification of Fabric Underlay Configuration on the Migrated 5-stage Clos Fabric
Verification of Fabric Physical Underlay and Overlay Topology on the Migrated 5-stage Clos Fabric
Operations Allowed on a Fabric in Migrate-failed State
Operations Allowed on a Fabric in Migrate-success State
Operations not Allowed on a Fabric in Migrate-success and Migrate-failed State
Conditions Supporting Fabric Migration
Conditions Not Supporting Fabric Migration
Supported Topology
Non-Clos Small Data Center Overview
Supported Small Data Center Topologies
Configure a Small Data Center Fabric
Dynamic ICL in Small Data Center
Overview of Day-0 Operations for a Small Data Center Fabric
Configure Local Bias for Handling the LVTEP BUM Traffic
IP Multicast Fabric Provisioning
IP Multicast Fabric Overview
Bidirectional Forwarding Detection
Fabric Settings to Update BGP MD5 Password, BGP Dynamic Peer Listen Limit, and Single Rack Deployment
Configure an IP Multicast Fabric
Device Configuration
Configure Drift and Reconcile on Multicast Fabric
View Fabric Details
Edit Fabric Settings
Update md5-password on an Active Fabric
Update bgp-multihop on an Active Fabric
Fabric Configuration using Force
Fabric DRC using Force
Fabric Event Handling
Brownfield Fabric Service Overview
Pre-validation of Configuration
Global Device Configuration
Interface Configuration
MCT Configuration
Overlay Gateway Configuration
EVPN Configuration
BGP Configuration
BGP Tables
BGP Events
Tenant Service Provisioning
Tenant Services Provisioning Overview
Clos Fabric with Non-auto VNI Maps
Clos Fabric with Auto VNI Map
Provision a Tenant Entity
Create a Tenant
Update a Tenant
Show a Tenant
Delete a Tenant
Configure a Tenant
Create a Private Tenant
Create a Shared Tenant
Scalability
VLAN-based Tenant
Bridge domain-based Tenant
Provision a Port Channel
Create a Port Channel
Update a Port Channel
Delete a Port Channel
Show a Port Channel
Configure a Port Channel
Configure Description on Port Channel
Configure Minimum Link Count on Port Channel
Configure MTU on Port Channel
Configure LACP-timeout on Port Channel
Configure Port on a Port Channel
Shared and Private Port Channel Configuration
Provision a VRF
Create a Tenant VRF
Update a Tenant VRF
Show a Tenant VRF
Delete a Tenant VRF
Shows a Tenant VRF Error
Configure a Tenant VRF
Configure Local ASN on Tenant VRF
Update Local ASN on VRF
Enable Graceful Restart on Tenant VRF
Configure MaxPaths on Tenant VRF
Configure Resilient Hashing on Tenant VRF
Configure Redistribute Attribute on Tenant VRF
Configure Advertise Network and Static Network on Tenant VRF
Configure Aggregate Address on Tenant VRF
Configure EVPN IRB VE Cluster Gateway on a Tenant VRF
Route Distinguisher (RD) Allocation Independent of Route Target (RT)
IPv6 Anycast Gateway Support
Configure Static VRF Route
Configure BFD on Static VRF Route
Configure Backup Routing on Tenant VRF
Distributed and Centralized Routing
Prepare Clos Fabric for Centralized Routing
Prepare Small Data Center Fabric for Centralized Routing
Enable Centralized Routing on Tenant VRF
Configure Physical Router for Centralized Routing on Tenant VRF
Configure Anycast IP on Tenant Endpoint Group
Configure Local IP on Tenant Endpoint Group
Configure Static Route on Tenant VRF
Configure Static Route BFD on Tenant VRF
Configure Peer Group on Tenant BGP
Configure Static Peer on Tenant BGP
Configure Dynamic Peer on Tenant BGP
Centralized Routing on Single Rack Small Data Center Leaf Pair (not Border Leaf Pair)
BFD Timers for Router BGP BFD and Static Route BFD Sessions
Provision a Tenant Endpoint Group
Create a Tenant Endpoint Group
Update a Tenant Endpoint Group
Show a Tenant Endpoint Group
Delete a Tenant Endpoint Group
Configure Network Property Description on Tenant EPG
Configure Network Property on Tenant EPG
IP DHCP Relay on Tenant EPG
XCO Provisioning of DHCP Relay Server and Gateway
Configure Port Property on Tenant EPG
Enable or Disable ICMP Redirect on Tenant EPG Networks
Update Anycast IP on an Existing Tenant Network
Configure Multiple Anycast IP
Configure IPv6 Neighbor Discovery (ND) on a Tenant Network
Configure BFD Session Type for an Endpoint Group
Configure Cluster Edge Port (CEP) Cluster Tracking for Endpoint Groups
Enable Cluster Tracking on CEP Interfaces
Configure Suppress Address Resolution Protocol and Neighbor Discovery on VLAN or Bridge Domain
Configure Local IP for Endpoint Group
EPG: Network Property: IP MTU
IPv6 Anycast Gateway Support
Software BFD Session Support on CEP
Provision a BGP Peer
Create BGP Static Peer
Add Path on Tenant BGP Peer
Create BGP Dynamic Peer
Configure Listen Limit on BGP Dynamic Peer
Force Delete the Associate Dynamic Peers on a Tenant BGP Peer Group
Getting the Operational State of the BGP Peers
Configure Route Map Attribute
Configure remove-private-as on BGP Peer
Configure default-originate to Advertise Default Route on BGP Peer
Configure Backup Routing Neighbors on BGP Peer
Configure Send-Community on Tenant BGP Peer
Configure Out-of-band for a Tenant BGP Peer or Peer Group
Provision a BGP Peer Group
Create a BGP Peer Group
Configure IP Prefix List and Route Map on Tenant BGP Peer Group
Configure Send-Community on Tenant BGP Peer Group
Add Path on Tenant BGP Peer Group
Configure remove-private-as on BGP Peer Group
Share Resources Across Tenants using Shared Tenant
Shared VRF and Router
Configure Shared Tenant, Shared VRF, and Private EPG using Shared VRF
Configure L3-Hand-Off EPG and BGP Peer under Ownership of Shared Tenant
Shared VRF and Router Usecase with Examples
Sharing Multiple VRFs with the Same RT (route-target)
Configure Tenant Admin Access to Shared Tenant Resources or Entities
Administered Partial Success
Administratively Manage a Device State
Traffic Mirroring Overview
In-band Traffic Mirroring
Out-of-band Traffic Mirroring
Support Matrix
Provision a Traffic Mirror Session
Configure Port-Based Mirroring in a Multi-Tenant Architecture
Configure Flow-Based Mirroring in a Multi-Tenant Architecture
Access Control List and Data Consistency Support
Configure VLAN-Based Mirroring in a Multi-Tenant Architecture
Configure ICL Port Mirroring in a Multi-Tenant Architecture
Configure Fabric Non-ICL Ports as Mirror Source
Exclusion of VLANs and Bridge from Cluster Instance
In-flight Transaction Recovery
Scalability
Policy Service Provisioning
Policy Service Provisioning Overview
Prefix List
Configure IP Prefix List on Devices
Drift and Reconcile (DRC) and Idempotency for IP Prefix List Configuration
Drift and Reconcile (DRC) for IPv6 Prefix List
Route Map
Configure Route Map on devices
Drift and Reconcile (DRC) and Idempotency for Route Map Configuration
Event Handling for IP Prefix List
Community List
Configure Standard Community List
Rollback Support
Configure Extended Community List
Configure Large Community List
Drift and Reconcile (DRC), Idempotency for Standard and Extended Community-list Configuration
Route Map Match and Set of Community List
Configure Route Map Match and Set of Community List
Drift and Reconcile (DRC) and Idempotency for Route Map Match and Set Configuration
Route Map Match and Set of Large Community List
Configure Route Map Match
Configure Route Map Set
Drift and Reconcile (DRC), Idempotency for Route Map Configuration for Large Community List
Policy Configuration Rollback
Policy Incremental Updates
Policy Device Membership Updates
Provisioning Dependencies
XCO Device Management
Device Image Management
Hitless Firmware Upgrade
Super-Spine Firmware Upgrade in Clos
Spine Firmware Upgrade in Clos
Firmware Upgrade of an MCT Leaf Pair with Dual-Homed Servers in Clos
Firmware Upgrade of a Three-Rack Centralized MCT Pair in Small Data Center
Firmware Upgrade of a Three-Rack Ring MCT Pair in Small Data Center
Firmware Download
Firmware Upgrade with Minimal Traffic Loss
Firmware Download Restart on HA Failover or Inventory Service Restart
Firmware Download Implicit Fullinstall Support
XCO Command Blocking during Firmware Download
Failures During Group-based Firmware Download Execution
Group-based Firmware Download Restore
Fabric-wide Firmware Download
Group-based Firmware Download Preparation
Fabric-based Firmware Download Preparation
Group-based Firmware Download Execution
Roll Back Device Firmware
Traffic Loss Scenarios
Device Health Management
Monitor Device Health
Device Configuration Backup and Replay
Configure Backup and Replay
Return Material Authorization
Replace a Faulty Device
SLX Device Configuration
Enable Maintenance Mode on SLX Devices
Configure Physical Port Speed
Configure Breakout Ports
Configure MTU at the Interface or System Level
Change the Admin Status of an Interface
Configure NTP at Device and Fabric Levels
Configure RME on Interface
Device Configuration Synchronization
SLX Configuration Backup
CLI Commands for Backups
XCO Native Support for SLX Threshold Monitor Settings
Set Threshold Monitor Options
Unset Threshold Monitor Settings
Display Threshold Monitor Settings
XCO Event Management
RASlog Service
RASlog Operations
Notification Service
Notification Types
Notification Sub-Filtering
Terminology
Additional Notification Filtering
Sub-Filter CLI
Sub-Filter Options during XCO Upgrade
Webhooks Payload
Syslog Subscribers Message Format
App Events RFC-5424 Format
Device Events RFC-5424 Format
XCO as SNMP Proxy
Configure SNMP View and Destination UDP Port
Drift and Reconcile (DRC) and Idempotency for SNMP
Unified Health and Fault Management
Unified Health and Fault Management Overview
Hierarchical Representation of Resources
Unified View of Health and Fault Updates
Fault Management - Alerts
Common Alert Payload to be Published via Syslog
Common Alert Payload to be published via Webhook
Alert Commands
Inventory of Alerts
Alert Details
Alarm Alerts
Backup and Restore Alerts
Certificate Alerts
Device Connectivity Alerts
High Availability Alerts
Login Alerts
LDAP Alerts
Storage Alerts
Upgrade Alerts
Missed Alerts
Alert Order
Fault Management - Alarms
Alarm Inventory
Alarm Status Change Notifications
Alarm Commands
Health Management
Bubbling of Health Status
Health Commands
Health APIs
Fabric Health
Fabric Health Calculation
Fabric Status
Fabric Level Physical Topology Health
Device Health
Sample Output of 3-stage Clos Fabric Creation
Known Limitations
Known Limitations in Fabric Skill
Policy Service Provisioning