cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
1
Helpful
1
Replies

ACI l3out EPG contract

Sureshbabu
Level 1
Level 1

Hi,

I have vrf PROD_VRF this vrf having vZany contract(consumer and provider common tenant). Same vrf using L3out , BD have EPG.

In L3out EPG have subnet - 10.0.0.0/8. This subnet host can access form EGP host with any L3 out EPG.

BD name- PROD_BD / BD - subnet 192.168.10.1/24

Source  - 192.168.10.X

destination - 10.0.0.X

Note: i dont have any contract on L3out EPG.

kindly suggest.

 

 

1 Accepted Solution

Accepted Solutions

Robert Burns
Cisco Employee
Cisco Employee

vzAny applies to both L3out EPGs as well as application EPGs.  Your behavior is expected - any External Subnet (10.0.0.0/8) will be able to access the EPG hosts (192.168.10.1/24)

Please read https://www.cisco.com/c/en/us/td/docs/dcn/ndo/3x/configuration/cisco-nexus-dashboard-orchestrator-configuration-guide-aci-371/ndo-configuration-aci-use-case-vzany-37x.pdf

Robert

View solution in original post

1 Reply 1

Robert Burns
Cisco Employee
Cisco Employee

vzAny applies to both L3out EPGs as well as application EPGs.  Your behavior is expected - any External Subnet (10.0.0.0/8) will be able to access the EPG hosts (192.168.10.1/24)

Please read https://www.cisco.com/c/en/us/td/docs/dcn/ndo/3x/configuration/cisco-nexus-dashboard-orchestrator-configuration-guide-aci-371/ndo-configuration-aci-use-case-vzany-37x.pdf

Robert

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License