cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1353
Views
5
Helpful
3
Replies

Cisco EPG Isolation and L3-Out External EPG Configurations Within a Preferred Groups Environment

zachartl
Level 1
Level 1

Hello,

We're using a Network Centric ACI Fabric VLANs = BD-EPG (1:1)

Most EPGs are members of the Preferred Groups

We're single Tenant and Single VRF fabric. Policy Enforcement is set to enabled. Policy enforcement direction is set to Ingress. The default. We're using a single primary L3-Out with one External EPG set for these Subnets - 0.0.0.0/1 and 128.0.0.0/1 (external subnets for the EPG). This EPG is a Preferred Groups Member.

Recently, we've been asked to isolate two EPGs within the fabric and so we've taken those two EPGs, having set them to be excluded from the Preferred Groups. Would it be possible to create a Second External EPG, configured as a Preferred Groups Member, using a more precise subnet 10.0.0.0/8 (external subnets for the EPG) without affecting the data plane traffic managed by the Primary External EPG? We would of course be equipping the Second External EPG with a consumed contract, the isolated EPGs being the contract provider/s. Please note, the 10.0.0.0/8 subnet covers most of our internal networks outside and within the ACI fabric. The point of this query, regards fabric external data plane traffic. Avoiding the disruption of that traffic already in place.

Thank you,

Terry

2 Accepted Solutions

Accepted Solutions

Sergiu.Daniluk
VIP Alumni
VIP Alumni

As long as you configure everything (contracts, preferred group) before configuring the eepg subnet, yes, you should be fine.

 

Stay safe,

Sergiu

View solution in original post

Hi Sergiu,

 

I will begin the configuration then for the new provisions. Thank you for having helped us with this issue.

 

Warmest Regards,

Terry

View solution in original post

3 Replies 3

Sergiu.Daniluk
VIP Alumni
VIP Alumni

As long as you configure everything (contracts, preferred group) before configuring the eepg subnet, yes, you should be fine.

 

Stay safe,

Sergiu

Hi Sergiu,

 

I will begin the configuration then for the new provisions. Thank you for having helped us with this issue.

 

Warmest Regards,

Terry

Hello Sergiu,

 

I inadvertently, somehow, made my post the Solution to the L3-Out challenge I was facing. Please know that was never the intent as You provided the Solution. Again, Thank You Greatly and I apologize for my apparent inability to operate this interface.

 

Warmest Regards,

Terry

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Save 25% on Day-2 Operations Add-On License