Cisco ACI based environment conflicting with the VIP in Aria Operations for Logs
book
Article ID: 315988
calendar_today
Updated On:
Products
VMware Aria Suite
Issue/Introduction
Symptoms:
The Administration > Management > System Monitor page intermittently shows Failed to load resources and agents are reporting Disconnected in a Cisco ACI based environment.
Aria Operations for Logs VIP is not reachable for ingestion, however ingestion sent directly to a node succeeds.
The liagent log contains the following error
Transport error while trying to ingest SSL connect error
The Aria Operations for Logs load balancer uses a Direct Server Return (DSR) configuration.
By default, DSR does not work in Cisco ACI because of data-plane IP learning.
Resolution
The L4-L7 Virtual IPs option was introduced in Cisco Application Policy Infrastructure Controller (APIC) Release 1.2(1m). This option is located at Tenant > Application Profiles > Application EPGs or uSeg EPGs. This option disables data-plane IP learning for the specific DSR virtual IP address. Failure to disable IP learning for the DSR virtual IP address will result in IP endpoint flapping between different locations in the Cisco ACI fabric.