cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
756
Views
0
Helpful
1
Replies

EPG isolation - Oracle VM using LINUX7

I am playing around with the isolation of an EPG feature, but as of yet I can't get my 2 x EP's isolated from each other. 

NB: They are coming off the same Interface, does that make a difference? Same EPG/BD/VRF. 

The port only has an encapsulation VLAN, no 2ndary.

Contracts are enforced, with EPG isolation selected.

 

I want to totally isolate the VM's in the EPG so that they don't communicate with any other EP in that EPG. 

1 Reply 1

RedNectar
VIP Alumni
VIP Alumni

Hi @crispin.robinson ,

First a tip:


When posting on the forum, add your pictures inline (click the Camera icon and simply click in, then paste your picture in the grey area of the dialogue that appears, or select the files.) This means you pictures are actually SEEN (a) in the email that gets sent to subscribers and (b) anyone who looks at this post in the future. Adding pictures as attachments... puts your submission into the TL;DR category.


And now let's look at your statement


NB: They are coming off the same Interface, does that make a difference? Same EPG/BD/VRF. 


Yep. It sure does! What that means is that the two hosts are connected to each other via a L2 switch or (more likely in your case since they are VMs) a vSwitch

So therefore, the traffic BETWEEN these two hosts will NEVER reach an ACI leaf where the policy is enforced.

The FIX

I guess you could fix this by deploying Cisco's AVE vSwitch on your ESXi hosts, but that decision is best made at the initial deployment stage.

An easier way at this stage is to isolate one of the hosts into a different VLAN but leave it in the same EPG and there are a couple of approaches.

  1. Use microsegmentation - isolating one of the VMs via name (for example)
  2. Use a static mapping for ONE of the VMs

The Microsegmentation approach doesn't really keep them in the same EPG though

So the static approach would go like this

  1. In vMware, create a new portgroup mapped to a new VLAN
  2. Statically map ONE of your VMs to that portgroup
  3. Statically map that VLAN to the SAME EPG
    • And now you should be able to do the isolation

 

RedNectar aka Chris Welsh.
Forum Tips: 1. Paste images inline - don't attach. 2. Always mark helpful and correct answers, it helps others find what they need.

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License