cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
220
Views
0
Helpful
2
Replies

Vzany contracts with service graph and some specific

shady-magdy
Level 1
Level 1

we have a problem related to contracts that all epgs directed to firewall with PBR and vzany under vrf and there is some epgs with some specific ports under contracts we noticed that some of epgs that must be directed to firewall hit with the specific ports and not directed to firewall, what is the cause of these problem

2 Replies 2

AshSe
VIP
VIP

Hi @shady-magdy 

Before answering your query, may I ask you one question:

1. Do you want EPGs' traffic to be filtered by the firewall (contected through PBR) or you need vzany contract inside the ACI to allow the traffic?

Intention is to understand, your purpose of configuring both vzany contract and PBR to firewall.

AshSe

we have a vzany under VRF consumer and provider contracts some of these contracts have a service graph and some have specific ports, we want all traffic go through the firewall except of the Epgs that have specific ports, we noticed some of these epgs although we applied a service graph to contract to go through the service graph, they went through the specific ports through another contract  

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License