cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
464
Views
0
Helpful
3
Replies

uSeg EPG contracts deny

dijix1990
VIP
VIP

I have some questions

I tried to implement uSeg and didn't understand behaviour

I have EPG APP with enforced behaviuor.

I made two uSeg epg and without contracts they couldn't speak each other - it's good. After it I permited RDP session between them through contract, RDP worked, but I noticed that PC's inside uSeg EPG could communicate with each other through any protocols.

I thought that deny is implicit rule in the contract

1 Accepted Solution

Accepted Solutions

dijix1990
VIP
VIP

so, it was because of vzAny rule, after was removing it started work as expected

View solution in original post

3 Replies 3

Robert Burns
Cisco Employee
Cisco Employee

Whether an endpoint belongs to a base EPG, or uSeg EPG doesn't impact how contracts work.  If you want endpoints between EPGs (Regular or uSeg) to communicate in a VRF in enforced mode - requires a contract.  The contract is what dicates the ports/protocols based on the associated filters of that contract. 

What does the filter in your applied contract look like?

Robert

My parent EPG (BKP_Servers_Test) - intra EPG isolation is Enforced

dijix1990_0-1701838248543.png

Now my endpoints can't communicate without contracts because of intra EPG isolation is Enforced, it's general behaviour

10.177.200.10 and 10.177.20.5

dijix1990_2-1701839431204.png

Now I want to move my 10.177.200.10 and 10.177.20.5 to different uSeg EPG

I made new uSeg-1 with match attribute ip=10.177.200.10 (placed inside uSeg-1), and after it 10.177.200.10 (placed inside paret EPG BKP_Servers_Test) could communicate with 10.177.200.5 without any contracts, why?

dijix1990_3-1701845178009.png

Is it default behavour? uSeg EPG and parent EPG can communicate without contracts? I thought that ACI has white list behaviour with feature intra EPG isolation is Enforced and we need contracts everywhere (for commication between different uSeg EPG, for communicate between uSeg EPG and Parent EPG for communicate between uSeg EPG and another EPG)

 

 

 

 

 

dijix1990
VIP
VIP

so, it was because of vzAny rule, after was removing it started work as expected

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License