Create an Ingress Group

An ingress group is a set of ports and port channels on which monitored traffic is received.

Before you begin

If applicable, create the port channel to associate with the ingress group. For more information, see Create a Port Channel.

Create the ingress policy to associate with the ingress group. For more information, see Create an Ingress Policy for a Device.

About this task

Ingress groups classify and apply policies on monitored traffic. After you create an ingress group, the group can be associated with an ingress policy.

Procedure

  1. In the Navigation menu, select Configure.
  2. In the Devices panel, select the device for which you want to create a policy.
  3. In the Device Config menu, select Add Ingress Group.
  4. In the Name field, enter a name for the group.
  5. In the Ports/Port Channels field, select at least one port or port channel for the group.
  6. In the Tunnel Type field, select the type of tunnel for the incoming traffic: GRE, GTPU, VXLAN, NVGRE, or IPIP.
  7. In the Tunnel ID field, select or enter a value that represents the tunnel ID.
    This field is not applicable for GRE and IPIP tunnels.
  8. In the Advance Scope section, select one of the following actions to apply to the incoming traffic.
    • Decap to remove the outer tunnel headers from the packet
    • Scope Shift to move the ACL scope for matching from the outer headers to the inner headers of a tunneled packet
    • None to perform neither action
  9. In the Policy Name field, select the ingress policy to associate with the ingress group.
  10. Save () your selections.
    The Configuration tab displays a graphical representation of the ingress group and its associated policies and egress groups (also known as a service chain).