cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1685
Views
10
Helpful
3
Replies

uSeg EPG Creation

a12288
Level 3
Level 3

We have few application EPGs under a same BD domain, and like to create a uSeg EPG based on VM tag, like DEPT=HR for example.

 

I believe we need to check "Allow Micro Segmentation" in the "VMM Domain Association" part. The uSeg EPG is created and VMs can move into this new uSeg EPG should its VM TAG DEPT=HR condition meets. But we found out 2 Private VLANs are created at the "base" EPG / PortGroup, hence, the rest VMs cannot communicate with each other, just like enable Intro-EPG Isolation.

 

Is this behavior expected, or we did something wrong? Thanks.

 

Leo

1 Accepted Solution

Accepted Solutions

Performance no but scalability yes. Go by the scale guides:

 

https://www.cisco.com/c/en/us/support/cloud-systems-management/application-policy-infrastructure-controller-apic/tsd-products-support-series-home.html

 

As far as contract scalability should be the same between uSeg and normal EPGs.

 

 

View solution in original post

3 Replies 3

micgarc2
Cisco Employee
Cisco Employee
To set this up you have to "Allow Micro-Segmentation’ on the  base EPG to VMM Domain association. This puts the base EPG in PVLAN mode. Once you add an attribute to the uSeg EPG and it matches the VM is no longer learnt in base EPG and moves to micro EPG.
 

Traffic is now not allowed between a VM in a base EPG and VMs in the microseg EPG. This will require contract to allow the communication.

Thanks for your further explanation, by putting the base EPG into PVLAN mode.

 

Then any communications between 2 VMs will be forwarded to upstream Leaf and handled by Leaf, will this cause any potential performance or scalability issues if the the number of PVLANs increase? Is there any rule of thumb in terms of micr-segmentation design? thanks.

 

Leo

Performance no but scalability yes. Go by the scale guides:

 

https://www.cisco.com/c/en/us/support/cloud-systems-management/application-policy-infrastructure-controller-apic/tsd-products-support-series-home.html

 

As far as contract scalability should be the same between uSeg and normal EPGs.

 

 

Save 25% on Day-2 Operations Add-On License