cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
619
Views
0
Helpful
2
Replies

Tool for Converting Cisco ACI Contract Filter into ASA Access List

fajar.alhafidh
Level 1
Level 1

Dear Cisco,

 

We have ACI with Application Centric Deployment that use Contract for communication between EPGs, Since this policy cause TCAM exhaustion we want to move the security part to the ASA Firewall using an Service Graph PBR. 

 

Is there any tools that we can use to convert the Contract filter on ACI to move into an access list on ASA devices ? 

2 Replies 2

julian.bendix
Level 3
Level 3

Hello!

Not to my knowledge - no.

 

Sorry and best regards

Julian

Robert Burns
Cisco Employee
Cisco Employee

This doesn't exist. There's vast differences between an ACL on ACI and legacy security devices.   Namely, ACI doesn't align policy with networking constructs (VLANs/MAC/IPs/Subnets) alone.  The EPG (source classID) is what's used to apply security ACLs (Protocols/Ethertypes etc) on a source/destination so an ACL (filter/contract) on ACI != ACL on ASA

Robert

Save 25% on Day-2 Operations Add-On License