05-24-2021 07:50 AM
Hello,
I have a EPG configured in L2 BD (ACI is not the DG of this subnet), and i have activated Intra-EPG isolation with a Intra-EPG contract to control the permited traffic, but it don't work. Is it a supported configuration?, are there any documentation for it?.
Regards.
Solved! Go to Solution.
05-25-2021 07:19 AM - edited 05-25-2021 07:19 AM
No its not supported. for Proxy arp to work, the BD needs to be L3. (SVI + Unicast Routing).
Robert
05-24-2021 08:35 AM
You can attach some screenshots of your config here.
05-24-2021 09:15 AM
05-24-2021 10:19 AM
What about your associated domain part of config?
05-24-2021 12:16 PM
05-24-2021 04:10 PM
Which version and Leaf models are you using?
Robert
05-24-2021 10:55 PM
Hi,
Version 5.1.3 and leaf FX (93180YC and 93108TC).
Regards.
05-25-2021 05:24 AM
What exactly are you trying to accomplish? Are you trying to restrict Intra-EPG communication to just ICMP? (Intra EPG Contract), or are you trying to prevent any communication within an EPG (Intra EPG Isolation)? If you just want to filter the Intra-EPG traffic, then all you need is the contract, not the isolation flag.
Robert
05-25-2021 05:35 AM
Hi,
I need permit specifict traffic in the EPG and deny rest, so I need Intra-EPG isolation for deny L2 traffic and Intra-EPG contract to permit specific traffic. This configuration works fine when ACI Bridge Domain has Unicast Routing enabled and IP configured in the BD, but for me don't work when the BD is L2.
The question is if this is supported.
Regards.
05-25-2021 07:05 AM
ACI is a zero trust environment when its Enforced.
when you create EPG where it says (intra EPG isolation) select "Enforced" and use contracts to allow traffic between EPG's
05-25-2021 07:19 AM - edited 05-25-2021 07:19 AM
No its not supported. for Proxy arp to work, the BD needs to be L3. (SVI + Unicast Routing).
Robert
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide