08-20-2020 02:13 PM
Hello,
I am trying to restrict communication between endpoints in different EPGs based on the IP addresses. Couldn't find the option to use IP address in the Filter. Can anyone please help to enable it? Thanks.
Qamber
Solved! Go to Solution.
08-20-2020 03:24 PM
Hi
you can’t do that using contracts.
You will need to configure useg EPG with attributes that will be your IP to classify your endpoints and then apply a contract.
A screenshot showing a test useg EPG:
Also a link of a CLUS presentation: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/LTRACI-2800.pdf
08-20-2020 10:43 PM
Hi @sqambera
As @Francesco Molino mentioned, the contracts do not have IP filter. If you want to apply a contract between specific IP addresses, you can try to use normal EPGs, but is quite tedious to design and maintain the design of your EPGs to meet the requirements. However, if you want to group your endpoints based on IP or subnet, you have two alternatives: uEPG and ESG.
ESG starts to be supported in version 5.0 and has the flexibility to group EPs across the VRF, compared with the uEPG which only permits microsegmentation inside the BD.
Comparison:
Reference to uEPG and ESG documentation:
Stay safe,
Sergiu
08-20-2020 03:24 PM
Hi
you can’t do that using contracts.
You will need to configure useg EPG with attributes that will be your IP to classify your endpoints and then apply a contract.
A screenshot showing a test useg EPG:
Also a link of a CLUS presentation: https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2017/pdf/LTRACI-2800.pdf
08-21-2020 08:27 AM
Thank you for the help!
08-20-2020 10:43 PM
Hi @sqambera
As @Francesco Molino mentioned, the contracts do not have IP filter. If you want to apply a contract between specific IP addresses, you can try to use normal EPGs, but is quite tedious to design and maintain the design of your EPGs to meet the requirements. However, if you want to group your endpoints based on IP or subnet, you have two alternatives: uEPG and ESG.
ESG starts to be supported in version 5.0 and has the flexibility to group EPs across the VRF, compared with the uEPG which only permits microsegmentation inside the BD.
Comparison:
Reference to uEPG and ESG documentation:
Stay safe,
Sergiu
08-21-2020 08:28 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide