cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5437
Views
5
Helpful
4
Replies

Forming Contract between L3out EPG and other EPGs within a AP with 1.1(3f)

petar.forai1
Level 1
Level 1

Hi

I cant figure out how to form a contract between a routed L3 out and the APs other EPGs. Within the AP I've added the external L3 domain to the domains. But I cant figure out how to form a contract between external L3 out and an internal EPG. The docs reference 1.0 in many places and there external EPGs and the domain enforcement within the EPG seem to be a bit different.

4 Replies 4

Robert Correiro
Level 1
Level 1

Hi petar.forai1,

 

There are a few configuration steps you'll need to follow.

 

(1) Create a contract, with an associated subject. The subject will contain filters and corresponding filter entries.

 

(2) Within the Application Profile, under the EPG, right click on the "Contracts" folder and select either "Add Provided Contract" or "Add Consumed Contract" depending on your desired traffic flow.

 

(3) Within the External Routed Network (L3 Out), on the External Network Instance Profile you created, make sure the Subnets listed have the "Security Import Subnet" option checked. This option is required to enforce policy on those subnets (via contracts) for traffic coming in/going out of the L3 out.

 

(4) Within the External Routed Network (L3 Out), on the created External Network Instance Profile, go to the Contracts tab towards the upper right of the work pane. Here you can apply the contract you created earlier to the L3 Out as either provided, consumed, or both.

 

You're enforcing policy between the internal EPG and the External EPG (device traffic coming in through the L3 Out) by having the contract on both.

 

Also, please let me know which documents you're referencing. If they are unclear or need updating, I can work towards improving them.

 

Hope this helps.

Hi Robert,

Thanks for your explanation. Is it normal that I don't see the L3ext icon (the L3 ext cloud icon for extrenal EPGs) within an AP that needs to talk to L3 ext out? I should mention that I'm not in the common tenant and I needed to replace the bridge domain and private network to get L3 ext connectivity (since the L3ext is configured under common tenant and one of it's private networks/contexts). 

 

TIA,

P

Hi Petar,

What tenant are the "private networks" in that you are wanting to make the common L3Ext accessable to?

If they are in the mgmt tenant, this is not possible.  The mgmt tenant is a special type of tenant and cannot access anything outside of itself.

@vbootstrap

Hello,

 

Could you please aleborate on the following

 

(2) Within the Application Profile, under the EPG, right click on the "Contracts" folder and select either "Add Provided Contract" or "Add Consumed Contract" depending on your desired traffic flow.

 

Do I have to apply both contracts on consume and provide direction? Or either is enough?

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License