cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

296
Views
5
Helpful
3
Replies
zachartl
Beginner

Cisco EPG Isolation and L3-Out External EPG Configurations Within a Preferred Groups Environment

Hello,

We're using a Network Centric ACI Fabric VLANs = BD-EPG (1:1)

Most EPGs are members of the Preferred Groups

We're single Tenant and Single VRF fabric. Policy Enforcement is set to enabled. Policy enforcement direction is set to Ingress. The default. We're using a single primary L3-Out with one External EPG set for these Subnets - 0.0.0.0/1 and 128.0.0.0/1 (external subnets for the EPG). This EPG is a Preferred Groups Member.

Recently, we've been asked to isolate two EPGs within the fabric and so we've taken those two EPGs, having set them to be excluded from the Preferred Groups. Would it be possible to create a Second External EPG, configured as a Preferred Groups Member, using a more precise subnet 10.0.0.0/8 (external subnets for the EPG) without affecting the data plane traffic managed by the Primary External EPG? We would of course be equipping the Second External EPG with a consumed contract, the isolated EPGs being the contract provider/s. Please note, the 10.0.0.0/8 subnet covers most of our internal networks outside and within the ACI fabric. The point of this query, regards fabric external data plane traffic. Avoiding the disruption of that traffic already in place.

Thank you,

Terry

2 ACCEPTED SOLUTIONS

Accepted Solutions
Sergiu.Daniluk
VIP Engager

As long as you configure everything (contracts, preferred group) before configuring the eepg subnet, yes, you should be fine.

 

Stay safe,

Sergiu

View solution in original post

Hi Sergiu,

 

I will begin the configuration then for the new provisions. Thank you for having helped us with this issue.

 

Warmest Regards,

Terry

View solution in original post

3 REPLIES 3
Sergiu.Daniluk
VIP Engager

As long as you configure everything (contracts, preferred group) before configuring the eepg subnet, yes, you should be fine.

 

Stay safe,

Sergiu

View solution in original post

Hi Sergiu,

 

I will begin the configuration then for the new provisions. Thank you for having helped us with this issue.

 

Warmest Regards,

Terry

View solution in original post

Hello Sergiu,

 

I inadvertently, somehow, made my post the Solution to the L3-Out challenge I was facing. Please know that was never the intent as You provided the Solution. Again, Thank You Greatly and I apologize for my apparent inability to operate this interface.

 

Warmest Regards,

Terry

Content for Community-Ad