cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1437
Views
0
Helpful
4
Replies

Isolation inside DNA Scalable Group?

JAN DEVOS
Level 2
Level 2

Hello, 

Is there a means to deny traffic between endpoints belonging to the same Scalable Group?  This for the obvious reason to prevent lateral movement between SG members.  I am looking for the lookalike of ACI's 'Intra EPG isolation'.  

4 Replies 4

Hi

  Dont think so.  The permit or deny happens actually on the Access Contract which is associated to a Scalable Grupo. I mean, in order do differentiate devices, you´ll need differentiate Scalable Grupo.

 

Roddie Hasan
Cisco Employee
Cisco Employee

Hi Jan,

Yes, this has been fully-supported since Day 1.  It is a very common strategy in guest networks where you don't want guest endpoints talking to each other.  It's simply a matter of creating a deny policy using the same SGT for source and destination.

I hope that helps.

Roddie

Tx, Roddie. This way of defining intra-SG-isolation (by deny any <SG> <SG>, where SG is one and the same scalable group) sounds logic. I did not think enough 'out of the box'., to find this solution by myself  This merits to be documented somewhere, no?

> This merits to be documented somewhere, no?

You're right, it should be - It's been a while since I looked at any of our guidance around policy, but I will do some digging to see if we have a CVD for it.

This strategy is definitely used widely.

Roddie