cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1087
Views
0
Helpful
4
Replies

Control with in same EPG

imalvi
Level 1
Level 1

Hi,

I have a question, one of the customer is asking for having control with in same EPG. For example if there is an EPG_FE with multiple VMs in it.How can we block access between these VMs under the same VLAN or EPG in ACI fabric?

Customer only have DVS in vcenter env.  

4 Replies 4

Tomas de Leon
Cisco Employee
Cisco Employee

In ACI version 1.2(1i) or later, There is a feature "Microsegmentation".

http://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/virtualization/b_ACI_Virtualization_Guide_1_2_1x/b_ACI_Virtualization_Guide_1_2_1x_chapter_01000.html

Microsegmentation with Cisco ACI provides support for virtual endpoints attached to Cisco Application Virtual Switch (AVS) and for Microsoft vSwitch using the OpFlex protocol. This feature is not available with VMware DVS.

So unfortunately for your customer this feature will not work.  A way you can still do this is create multiple EPGs within the same BD and use contracts to enforce policy.

Cheers!

T.

Robert Burns
Cisco Employee
Cisco Employee

In addition to what Tomas mentioned, there is an Intra-EPG isolation feature on the roadmap which is targeting the next major release.  No ETA at this point, but its coming. 

Robert

Thank you Tomas and Robert for the clarification. So AVS is the way to go unless new release comes up with micro-segmentation for DVS.

Thanks.

Regards

Imran

Hi Robert,

Just to see if I understood you correctly .... If I have two bare metal servers in the same EPG, Intra-EPG isolation is not available at the current latest release ... yet (by the way I'm running 1.2(1i) ... correct ?

Regards,

Bruno Fernandes

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License