Resource Orchestrator provides sample rulesets for the L2 switch used in the standard model in which firewalls and server load balancers are used. The sample ruleset names are shown below.
For the SR-X 300 series
For the systems with tagged VLAN networks configured
A tagged VLAN is set for a port using tag_vlan_port--SR-X300 or tag_vlan_port--SR-X300_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | tag_vlan_net--SR-X300 |
%UP_PORT1% | Change this to the physical port number connected to the firewall or the server load balancer. | tag_vlan_net--SR-X300 |
Change this to the physical port number connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X300_2 | |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X300_3 | |
%UP_PORT2% | Change this to the physical port number connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X300_2 |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT1%. | tag_vlan_net--SR-X300_3 | |
%UP_PORT3% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X300_3 |
%UP_PORT4% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT3%. | tag_vlan_net--SR-X300_3 |
%DOWN_PORT1% | Change this to the number of the physical port connected to the server. | tag_vlan_net--SR-X300 |
Change this to the physical port number of the LAG connected to the server. | tag_vlan_net--SR-X300_3 | |
%DOWN_PORT2% | Change this to the physical port number of the LAG connected to the server. Note that this port number must not be the same as that of %DOWN_PORT1%. | tag_vlan_net--SR-X300_3 |
For an SR-X 300 series that sets a tagged VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
For the systems with untagged VLAN networks configured
A port VLAN is set for a port by using untag_vlan_port--SR-X300 or untag_vlan_port--SR-X300_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | untag_vlan_net--SR-X300 |
%UP_PORT1% | Change this to the physical port number connected to the firewall or the server load balancer. | untag_vlan_net--SR-X300 |
Change this to the physical port number connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X300_2 | |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X300_3 | |
%UP_PORT2% | Change this to the physical port number connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X300_2 |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT1%. | untag_vlan_net--SR-X300_3 | |
%UP_PORT3% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X300_3 |
%UP_PORT4% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT3%. | untag_vlan_net--SR-X300_3 |
%DOWN_PORT1% | Change this to the number of the physical port connected to the server. | untag_vlan_net--SR-X300 |
Change this to the physical port number of the LAG connected to the server. | untag_vlan_net--SR-X300_3 | |
%DOWN_PORT2% | Change this to the physical port number of the LAG connected to the server. Note that this port number must not be the same as that of %DOWN_PORT1%. | untag_vlan_net--SR-X300_3 |
For an SR-X 300 series that sets a port VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
_n: Configuration differs depending on the number in n.
When _n is not specified: LAN channels are in a non-redundant configuration
When n is "2": LAN channels are in a redundant configuration
When n is "3": LAN channels are in a redundant configuration using link aggregation
For the SR-X 500 Series
For systems with tagged VLAN networks configured
A tagged VLAN is set for a port by using tag_vlan_port--SR-X500 or tag_vlan_port--SR-X500_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | tag_vlan_net--SR-X500 |
%UP_PORT1% | Change this to the physical port number connected to the firewall or the server load balancer. | tag_vlan_net--SR-X500 |
Change this to the physical port number connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X500_2 | |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X500_3 | |
%UP_PORT2% | Change this to the physical port number connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X500_2 |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT1%. | tag_vlan_net--SR-X500_3 | |
%UP_PORT3% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--SR-X500_3 |
%UP_PORT4% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT3%. | tag_vlan_net--SR-X500_3 |
%DOWN_PORT1% | Change this to the number of the physical port connected to the server. | tag_vlan_net--SR-X500 |
Change this to the physical port number of the LAG connected to the server. | tag_vlan_net--SR-X500_3 | |
%DOWN_PORT2% | Change this to the physical port number of the LAG connected to the server. Note that this port number must not be the same as that of %DOWN_PORT1%. | tag_vlan_net--SR-X500_3 |
For an SR-X 500 series that sets a tagged VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
For the systems with untagged VLAN networks configured
A port VLAN is set for a port by using untag_vlan_port--SR-X500 or untag_vlan_port--SR-X500_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | untag_vlan_net--SR-X500 |
%UP_PORT1% | Change this to the physical port number connected to the firewall or the server load balancer. | untag_vlan_net--SR-X500 |
Change this to the physical port number connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X500_2 | |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X500_3 | |
%UP_PORT2% | Change this to the physical port number connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X500_2 |
Change this to the physical port number of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT1%. | untag_vlan_net--SR-X500_3 | |
%UP_PORT3% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--SR-X500_3 |
%UP_PORT4% | Change this to the physical port number of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. Note that this port number must not be the same as that of %UP_PORT3%. | untag_vlan_net--SR-X500_3 |
%DOWN_PORT1% | Change this to the number of the physical port connected to the server. | untag_vlan_net--SR-X500 |
Change this to the physical port number of the LAG connected to the server. | untag_vlan_net--SR-X500_3 | |
%DOWN_PORT2% | Change this to the physical port number of the LAG connected to the server. Note that this port number must not be the same as that of %DOWN_PORT1%. | untag_vlan_net--SR-X500_3 |
For an SR-X 500 series that sets a port VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
_n: Configuration differs depending on the number in n.
When _n is not specified: LAN channels are in a non-redundant configuration
When n is "2": LAN channels are in a redundant configuration
When n is "3": LAN channels are in a redundant configuration using link aggregation
For the Catalyst series
For the systems with tagged VLAN networks configured
A tagged VLAN is set for a port by using tag_vlan_port--Catalyst or tag_vlan_port--Catalyst_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | tag_vlan_net--Catalyst |
%UP_PORT1% | Change this to the physical interface name connected to the firewall or the server load balancer. | tag_vlan_net--Catalyst |
Change this to the name of the physical interface connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Catalyst2 | |
Change this to the name of the physical interface of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Catalyst3 | |
%UP_PORT2% | Change this to the name of the physical interface connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Catalyst2 |
Change this to the name of the physical interface of the LAG connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Catalyst3 | |
%DOWN_PORT1% | Change this to the name of the physical interface connected to the server. | tag_vlan_net--Catalyst |
Change this to the name of the physical interface of the LAG connected to the server. | tag_vlan_net--Catalyst3 |
For a Catalyst series that sets a tagged VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
For the systems with untagged VLAN networks configured
A port VLAN is set for a port by using untag_vlan_port--Catalyst or untag_vlan_port--Catalyst_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | untag_vlan_net--Catalyst |
%UP_PORT1% | Change this to the physical interface name connected to the firewall or the server load balancer. | untag_vlan_net--Catalyst |
Change this to the name of the physical interface connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Catalyst2 | |
Change this to the name of the physical interface of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Catalyst3 | |
%UP_PORT2% | Change this to the name of the physical interface connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Catalyst2 |
Change this to the name of the physical interface of the LAG connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Catalyst3 | |
%DOWN_PORT1% | Change this to the name of the physical interface connected to the server. | untag_vlan_net--Catalyst |
Change this to the name of the physical interface of the LAG connected to the server. | untag_vlan_net--Catalyst3 |
For a Catalyst series that sets a port VLAN for the port connected to the firewall, the server load balancer, or the server
Register this ruleset in the specific ruleset registration folder of the network device.
_n: Configuration differs depending on the number in n.
When _n is not specified: LAN channels are in a non-redundant configuration
When n is "2": LAN channels are in a redundant configuration
When n is "3": LAN channels are in a redundant configuration using link aggregation
For the Nexus5000 series
Automatic configuration of Nexus 2000 series (except Nexus B22 Blade Fabric Extender) connected to Nexus 5000 series using a fabric interface is possible.
For the systems with tagged VLAN networks configured
A tagged VLAN is set for a LAN port using tag_vlan_port-- Nexus5000 or tag_vlan_port-- Nexus5000_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | tag_vlan_net--Nexus5000 |
%UP_PORT1% | Change this to the physical interface name connected to the firewall or the server load balancer. | tag_vlan_net--Nexus5000 |
Change this to the name of the physical interface connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Nexus5000_2 | |
Change this to the name of the logical interface of the link aggregation group (LAG) connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Nexus5000_3 | |
%UP_PORT2% | Change this to the name of the physical interface connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Nexus5000_2 |
Change this to the name of the logical interface of the link aggregation group (LAG) connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | tag_vlan_net--Nexus5000_3 | |
%DOWN_PORT1% | Change this to the name of the physical interface connected to the server. | tag_vlan_net--Nexus5000 |
Change the logical interface name of the LAG connected to the server. | tag_vlan_net--Nexus5000_3 |
When configuring a Nexus 2000 (excluding Nexus B22 Blade Fabric Extender) connected to a Nexus 5000 with fabric interface, set the physical interface name of the Nexus 2000 for the above parameter.
For a Nexus 5000 with a tagged VLAN configured for the port connected to the firewall, server load balancer, or server
Register this ruleset in the specific ruleset registration folder of the network device.
For the systems with untagged VLAN networks configured
A port VLAN is set for a port using untag_vlan_port-Nexus5000 or untag_vlan_port-Nexus5000_n.
Register this ruleset in the ruleset registration folder common to network devices.
The target of customizing is a parameter in all the related script lists.
The list of parameters that need to be customized is shown below.
Parameter File | Details of Modification | Ruleset Name |
node operand: | Change this to the network device name of the L2 switch registered in Resource Orchestrator. | untag_vlan_net--Nexus5000 |
%UP_PORT1% | Change this to the physical interface name connected to the firewall or the server load balancer. | untag_vlan_net--Nexus5000 |
Change this to the name of the physical interface connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Nexus5000_2 | |
Change this to the name of the logical interface of the link aggregation group (LAG) connected to the "Active" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Nexus5000_3 | |
%UP_PORT2% | Change this to the name of the physical interface connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Nexus5000_2 |
Change this to the name of the logical interface of the link aggregation group (LAG) connected to the "Standby" side of the firewall or the server load balancer of the redundant configuration. | untag_vlan_net--Nexus5000_3 | |
%DOWN_PORT1% | Change this to the name of the physical interface connected to the server. | untag_vlan_net--Nexus5000 |
Change the logical interface name of the LAG connected to the server. | untag_vlan_net--Nexus5000_3 |
When configuring a Nexus 2000 (excluding Nexus B22 Blade Fabric Extender) connected to a Nexus 5000 with fabric interface, set the physical interface name of the Nexus 2000 for the above parameter.
For a Nexus 5000 with a port VLAN configured for the port connected to the firewall, server load balancer, or server
Register this ruleset in the specific ruleset registration folder of the network device.
_n: Configuration differs depending on the number in n.
When _n is not specified: LAN channels are in a non-redundant configuration
When n is "2": LAN channels are in a redundant configuration
When n is "3": LAN channels are in a redundant configuration using link aggregation