04-06-2018 08:11 AM - edited 03-01-2019 05:30 AM
We have 7 EPGs created and mapped to 7 different bridge domains ( one to one mapping)
one L3Out for all these bridge domains
There is currently one EPG created with 0.0.0.0 for L3Out Networks and provided & consumed a default standard contract ( VRF enforced mode)
created new EPG & Bridge domain which required ISOLATED VLAN Access ( like permit only few external access( AD & DNS Servers which are reachable through L3Out and deny rest all).
We had plan to:-
(1) create New EPG to add AD & DNS Serevers under L3Out
(2) create new contract and add default filter
(3) provide and consume this new contract in new internal EPG and L3OutEPG
if We configure as above, Would ACI remove AD & DNS Servers from the existing L3Out EPG (which has network 0.0.0.0) and only consider these AD & DNS Servers in new L3Out EPG?
APIC version is 3.1(i). Could someone advise
Thank you in advance
Solved! Go to Solution.
04-07-2018 03:54 AM - edited 04-07-2018 03:59 AM
That’s right. The L3EPG pcTag and prefixes get programmed on all the leaves with L3Out EPG contracts in the VRF and traffic towards the L3 Outs are evaluates against these prefixes.
You could create the new L3EPG and add the contracts prior to adding the IPs to avoid downtime.
04-07-2018 03:42 AM
If you add the AD and DNS server IPs to the new L3 EPG then they will be matched there and no longer on the 0.0.0.0 L3 EPG.
04-07-2018 03:48 AM
04-07-2018 03:54 AM - edited 04-07-2018 03:59 AM
That’s right. The L3EPG pcTag and prefixes get programmed on all the leaves with L3Out EPG contracts in the VRF and traffic towards the L3 Outs are evaluates against these prefixes.
You could create the new L3EPG and add the contracts prior to adding the IPs to avoid downtime.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide