Bulk Onboarding Virtual Edges and Virtual Edge Nodes

This is a supplementary article for onboarding Elisity Virtual Edges and Virtual Edge Nodes that covers our Bulk Onboarding feature to make deployment scalable for large enterprises.

Exporting Configuration Settings for Re-Import

Cloud Control Center can export the configuration of your existing Virtual Edges and Virtual Edge Nodes as an import-compatible Excel (.xlsx) file. This lets you export the current configuration, edit it, and re-import it to apply changes at scale without re-entering every value by hand. On both the All Virtual Edges table and the Virtual Edge Node table, open the Export menu and select Export Configuration Settings.

The exported Virtual Edge file contains the following columns: Host Name, IP Address, Mask, VE Group, Description, Gateway IP, VLAN, DNS Servers, Site Label, and Distribution Zone. The Virtual Edge Group (VE Group) column is empty for standalone (single-node) Virtual Edges.

The exported Virtual Edge Node file contains: Management IP, Type, Virtual Edge Group, Virtual Edge, Credential-Set, Description, Site Label, Distribution Zone, Enable Flow Telemetry, Enable Endpoint Discovery, Enable Policy Enforcement, Enable Aggregation Role, Enable NAT Support, NAT Inside IP, and Additional Flow Exporter. The Virtual Edge Group column is empty for Virtual Edge Nodes that belong to a standalone Virtual Edge, and the Virtual Edge column is empty for Virtual Edge Nodes that belong to a Virtual Edge Group.

Bulk Onboarding Virtual Edges

Requirements

You should familiarize yourself with deployment requirements and the full deployment process for an individual Virtual Edge Node within each of our deployment methods prior to using our bulk onboarding feature. This feature allows you to provision your Virtual Edges and Nodes in Cloud Control Center all at once using an Excel data sheet rather than provisioning each Virtual Edge and Node Individually; additional steps are required outside of provisioning in Cloud Control Center. You can review our in-depth Virtual Edge Deployment Guides here:

Deploy Elisity Virtual Edge (Switch Hosted)

Deploy Elisity Virtual Edge VM (Hypervisor Hosted)

Onboarding Catalyst 9000/3850/3650 as a Virtual Edge Node

To begin, navigate to the Virtual Edge section in Cloud Control Center and click Add Virtual Edge. From here you will be presented with the option to add a single Virtual Edge or the option to add multiple Virtual Edges. Click "Add Multiple Virtual Edges" as seen in the screenshot below.

The Add Multiple Virtual Edges wizard first asks you to choose the hosting type for the Virtual Edges you are onboarding: Switch (Switch Hosted) or Virtual Infrastructure. There is a separate Excel template for each type, so it is important that you only enter information for the type of Virtual Edge you selected to ensure a successful onboarding. On the Virtual Edge Configuration step, click Download Sample to download the template, populate it, and then upload it on the same screen. The upload area accepts an Excel (.xlsx) file.

Open the template and fill out the required fields (marked with an asterisk) along with any optional fields:

  • Virtual Infrastructure: IP Address*, Host Name*, and VE Group* (the VE Group must already be configured in Cloud Control Center), plus an optional Description.
  • Switch (Switch Hosted): Host Name*, IP Address/Mask*, Gateway IP*, VLAN*, and DNS Servers*, plus optional Description, Site Label, and Distribution Zone. Site Label and Distribution Zone default to Default when left blank.

Any unexpected or extra columns in the spreadsheet are ignored during parsing.

After modifying the Excel file, save the file and upload it to Cloud Control Center on the same screen where you downloaded the template. Any configuration errors are checked and presented to you, who will then need to correct the flagged rows and re-upload.

If there are no further errors, you will see the confirmation that there are no errors and the submit button will be highlighted, which allows you to then submit your Virtual Edge upload.

From here, you need to finish the onboarding process for each Virtual Edge by following the corresponding guides, skipping the creation of Virtual Edges in Cloud Control Center. These guides can be found here.

Deploy Elisity Virtual Edge (Switch Hosted)

Deploy Elisity Virtual Edge VM (Hypervisor Hosted)

Bulk Onboarding Virtual Edge Nodes

Requirements

Be sure that each switch you want to onboard as a Virtual Edge Node meets these requirements, and has the appropriate admin credentials setup.

NOTE:

  • IOS-XE version 17.6.6a/17.9.4 is the minimum recommended code version
  • All switches being onboarded must have their clocks synchronized with the Active Directory server so that attachment events are displayed accurately. You can use your own NTP server or a public one such as time.google.com.
  • Catalyst series switches require a minimum of IPBase licensing to be onboarded as Virtual Edge Nodes.

CATALYST 9400 SPECIFIC NOTE:

  • Catalyst 9410 series switch. If the Catalyst 9410 being onboarded is hosting a Virtual Edge using the Application Hosting functionality, it is mandatory to disable Elisity identity on GigabitEthernet4/0/48. See disabling identity on select switchports in this article for instructions.

On each switch, you should either have a user account with privilege 15 configured or TACACS login configured to provide privilege 15 level access. This is needed for the Virtual Edge to authenticate with the switch. Execute the following command under global configuration mode if a local account is being used and is not already configured:

switch(config)# username <username> privilege 15 secret 0 <password>


Add the following commands to your switch configuration if using TACACS

switch(config)# aaa authentication login HTTP_AUTH group <group name> local
switch(config)# ip http authentication aaa login-authentication HTTP_AUTH

Bulk Onboarding Process

You can start bulk onboarding Virtual Edge Nodes in two ways.

Method 1: Select your Virtual Edge and Add VENs
Go to the Virtual Edge dashboard in Cloud Control Center and select the Virtual Edge you would like to work from.

After clicking on the VE, you can click on Add Virtual Edge Node and select Add Multiple Virtual Edge Nodes.

Method 2: Onboard VENs Directly from the Virtual Edge Node panel.

Select the Virtual Edge Node tab in the bottom menu, and select Add Virtual Edge Node then select Add Multiple Virtual Edge Nodes. The parent Virtual Edge or Virtual Edge Group for each node is set directly in the spreadsheet, so you do not select a parent Virtual Edge separately in this wizard.

Adding Multiple Virtual Edge Nodes

The Add Multiple Virtual Edge Nodes wizard first asks you to choose the Virtual Edge type and then presents a single configuration step where you download the template, populate it, and upload it. Click Download Template, fill in the required fields and any optional fields, and then upload the completed file on the same screen. The upload area accepts an Excel (.xlsx) file.

The parent Virtual Edge or Virtual Edge Group and the switch credentials are entered directly in the spreadsheet, so there are no separate steps for selecting a Virtual Edge or setting switch credentials.

The required data fields are marked with an asterisk. The following chart provides details about each column.

Management IP*

The primary interface IP address of the switch you wish to onboard as a Virtual Edge Node for policy enforcement. This IP must be reachable by the previously deployed Virtual Edge container. This field is mandatory.

Type*

The Virtual Edge Node type. Bulk import processes only Switch and WLC types; rows with any other value in the Type column are ignored during import. This field is mandatory.

Virtual Edge Group*

The name of the parent Virtual Edge Group for Virtual Edge Nodes onboarded under a multi-node Virtual Edge Group. Provide either Virtual Edge Group or Virtual Edge, depending on the parent.

Virtual Edge*

The name of the parent Virtual Edge for Virtual Edge Nodes onboarded under a single-node (standalone) Virtual Edge. Provide either Virtual Edge or Virtual Edge Group, depending on the parent.

Credential-Set*

The name of a Global Credentials entry configured in Cloud Control Center that the Virtual Edge Node uses to authenticate to the switch. Privilege 15 access is required. This field is mandatory.

Description

A user-defined description for the Virtual Edge Node. This field is optional and is left blank when not provided.

Site Label

Site labels can be applied to Virtual Edge Nodes for policy distribution and analytics purposes, and are used to assign Virtual Edges and Virtual Edge Nodes to Policy Sets. If this field is left blank, the Site Label is inherited from the parent Virtual Edge Group or Virtual Edge.

Distribution Zone

The Distribution Zone applied to the Virtual Edge Node. If this field is left blank, the Distribution Zone is inherited from the parent Virtual Edge Group or Virtual Edge.

Enable Flow Telemetry

Setting this option to TRUE enables the collection of flow data and network traffic analytics that are sent to Cloud Control Center. Defaults to TRUE when left blank. (Recommended)

Enable Endpoint Discovery

Setting this option to TRUE enables the collection of identifying data about endpoints discovered behind the Virtual Edge Node. Defaults to TRUE when left blank. (Recommended)

Enable Policy Enforcement

Setting this option to TRUE enables policy enforcement on the Virtual Edge Node. Defaults to TRUE when left blank.

Enable Aggregation Role

Setting this option to TRUE assigns the aggregation role to the Virtual Edge Node. Defaults to FALSE when left blank.

Enable NAT Support

Setting this option to TRUE enables NAT support on the Virtual Edge Node. Defaults to FALSE when left blank.

NAT Inside IP

The inside IP address used when NAT support is enabled. This field is optional and is left empty when not provided.

Additional Flow Exporter

An additional flow exporter destination for the Virtual Edge Node. This field is optional and is left empty when not provided.

NOTE:

When you bulk-onboard switch Virtual Edge Nodes, enter each switch's primary interface IP address in the Management IP column. During onboarding, Cloud Control Center runs an IP Address Check that confirms the configured IP is the primary address on the switch interface. A Management IP that is an HSRP, VRRP, or GLBP virtual address, or an IPv4 secondary address, fails the check and the Virtual Edge Node moves to Registration Failed. This applies to Cisco IOS-XE, Arista EOS, Aruba AOS-CX, and Juniper (direct). To recover, edit the Virtual Edge Node's Management IP to the primary interface address and onboarding re-runs automatically. For more detail, see Managing Virtual Edges and Virtual Edge Nodes.

Fill out these fields in the Excel sheet along with any additional data you want to include, save the file, and upload it in the same place that you downloaded the Virtual Edge Node onboarding template. Attempting to submit your spreadsheet reveals any issues with the configuration of your Virtual Edge Nodes. On the left-hand side of your list of Virtual Edge Nodes, a red indicator shows that something is wrong in that row, so you can easily find and note any issues with the configuration of your list of VENs.

Fix these issues in Excel or another editor, then save and re-upload until you have no errors.

After successfully uploading your file, you should begin to see Virtual Edge Nodes registered in Cloud Control Center. Some additional configuration may be required on each onboarded Node, you can find those details in our Onboarding Virtual Edge Nodes Article and our article for Onboarding Catalyst IE3400 Series Switches Article.

Was this article helpful?
0 out of 0 found this helpful