09-28-2018 06:18 AM - edited 03-01-2019 05:39 AM
We have few application EPGs under a same BD domain, and like to create a uSeg EPG based on VM tag, like DEPT=HR for example.
I believe we need to check "Allow Micro Segmentation" in the "VMM Domain Association" part. The uSeg EPG is created and VMs can move into this new uSeg EPG should its VM TAG DEPT=HR condition meets. But we found out 2 Private VLANs are created at the "base" EPG / PortGroup, hence, the rest VMs cannot communicate with each other, just like enable Intro-EPG Isolation.
Is this behavior expected, or we did something wrong? Thanks.
Leo
Solved! Go to Solution.
10-12-2018 06:17 AM
Performance no but scalability yes. Go by the scale guides:
As far as contract scalability should be the same between uSeg and normal EPGs.
10-02-2018 07:44 PM
Traffic is now not allowed between a VM in a base EPG and VMs in the microseg EPG. This will require contract to allow the communication.
10-12-2018 06:03 AM
Thanks for your further explanation, by putting the base EPG into PVLAN mode.
Then any communications between 2 VMs will be forwarded to upstream Leaf and handled by Leaf, will this cause any potential performance or scalability issues if the the number of PVLANs increase? Is there any rule of thumb in terms of micr-segmentation design? thanks.
Leo
10-12-2018 06:17 AM
Performance no but scalability yes. Go by the scale guides:
As far as contract scalability should be the same between uSeg and normal EPGs.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide