cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1778
Views
10
Helpful
4
Replies

ACI Contract

sqambera
Level 1
Level 1

Hello,

I am trying to restrict communication between endpoints in different EPGs based on the IP addresses. Couldn't find the option to use IP address in the Filter. Can anyone please help to enable it? Thanks.

 

Qamber

2 Accepted Solutions

Accepted Solutions

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

you can’t do that using contracts.

You will need to configure useg EPG with attributes that will be your IP to classify your endpoints and then apply a contract.

 

A screenshot showing a test useg EPG:

86FA2A60-9B45-45D5-982B-7C5B7F4898BC.jpeg

 

 

Also a link of a CLUS presentation: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/LTRACI-2800.pdf

 

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

Sergiu.Daniluk
VIP Alumni
VIP Alumni

Hi @sqambera 

 

As @Francesco Molino  mentioned, the contracts do not have IP filter. If you want to apply a contract between specific IP addresses, you can try to use normal EPGs, but is quite tedious to design and maintain the design of your EPGs to meet the requirements. However, if you want to group your endpoints based on IP or subnet, you have two alternatives: uEPG and ESG.

ESG starts to be supported in version 5.0 and has the flexibility to group EPs across the VRF, compared with the uEPG which only permits microsegmentation inside the BD.

Comparison:

  • ESG (right):

 

  • uEPG:

Capture1.PNG

 

Reference to uEPG and ESG documentation:

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/5-x/security/cisco-apic-security-configuration-guide-50x/m-endpoint-security-groups.html 

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/virtualization/b_ACI_Virtualization_Guide_2_1_1/b_ACI_Virtualization_Guide_2_1_1_chapter_0100.html 

 

Stay safe,

Sergiu

View solution in original post

4 Replies 4

Francesco Molino
VIP Alumni
VIP Alumni

Hi

 

you can’t do that using contracts.

You will need to configure useg EPG with attributes that will be your IP to classify your endpoints and then apply a contract.

 

A screenshot showing a test useg EPG:

86FA2A60-9B45-45D5-982B-7C5B7F4898BC.jpeg

 

 

Also a link of a CLUS presentation: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/LTRACI-2800.pdf

 

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thank you for the help!

Sergiu.Daniluk
VIP Alumni
VIP Alumni

Hi @sqambera 

 

As @Francesco Molino  mentioned, the contracts do not have IP filter. If you want to apply a contract between specific IP addresses, you can try to use normal EPGs, but is quite tedious to design and maintain the design of your EPGs to meet the requirements. However, if you want to group your endpoints based on IP or subnet, you have two alternatives: uEPG and ESG.

ESG starts to be supported in version 5.0 and has the flexibility to group EPs across the VRF, compared with the uEPG which only permits microsegmentation inside the BD.

Comparison:

  • ESG (right):

 

  • uEPG:

Capture1.PNG

 

Reference to uEPG and ESG documentation:

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/5-x/security/cisco-apic-security-configuration-guide-50x/m-endpoint-security-groups.html 

https://www.cisco.com/c/en/us/td/docs/switches/datacenter/aci/apic/sw/1-x/virtualization/b_ACI_Virtualization_Guide_2_1_1/b_ACI_Virtualization_Guide_2_1_1_chapter_0100.html 

 

Stay safe,

Sergiu

Thank you for the help Sergiu!

Review Cisco Networking for a $25 gift card