05-30-2022 04:17 AM
I am playing around with the isolation of an EPG feature, but as of yet I can't get my 2 x EP's isolated from each other.
NB: They are coming off the same Interface, does that make a difference? Same EPG/BD/VRF.
The port only has an encapsulation VLAN, no 2ndary.
Contracts are enforced, with EPG isolation selected.
I want to totally isolate the VM's in the EPG so that they don't communicate with any other EP in that EPG.
05-30-2022 02:41 PM
Hi @crispin.robinson ,
First a tip:
When posting on the forum, add your pictures inline (click the Camera icon and simply click in, then paste your picture in the grey area of the dialogue that appears, or select the files.) This means you pictures are actually SEEN (a) in the email that gets sent to subscribers and (b) anyone who looks at this post in the future. Adding pictures as attachments... puts your submission into the TL;DR category.
And now let's look at your statement
NB: They are coming off the same Interface, does that make a difference? Same EPG/BD/VRF.
Yep. It sure does! What that means is that the two hosts are connected to each other via a L2 switch or (more likely in your case since they are VMs) a vSwitch
So therefore, the traffic BETWEEN these two hosts will NEVER reach an ACI leaf where the policy is enforced.
I guess you could fix this by deploying Cisco's AVE vSwitch on your ESXi hosts, but that decision is best made at the initial deployment stage.
An easier way at this stage is to isolate one of the hosts into a different VLAN but leave it in the same EPG and there are a couple of approaches.
The Microsegmentation approach doesn't really keep them in the same EPG though
So the static approach would go like this
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide