cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
548
Views
0
Helpful
4
Replies

Isolation inside DNA Scalable Group?

JAN DEVOS
Level 1
Level 1

Hello, 

Is there a means to deny traffic between endpoints belonging to the same Scalable Group?  This for the obvious reason to prevent lateral movement between SG members.  I am looking for the lookalike of ACI's 'Intra EPG isolation'.  

4 Replies 4

Hi

  Dont think so.  The permit or deny happens actually on the Access Contract which is associated to a Scalable Grupo. I mean, in order do differentiate devices, you´ll need differentiate Scalable Grupo.

 

Roddie Hasan
Cisco Employee
Cisco Employee

Hi Jan,

Yes, this has been fully-supported since Day 1.  It is a very common strategy in guest networks where you don't want guest endpoints talking to each other.  It's simply a matter of creating a deny policy using the same SGT for source and destination.

I hope that helps.

Roddie

Tx, Roddie. This way of defining intra-SG-isolation (by deny any <SG> <SG>, where SG is one and the same scalable group) sounds logic. I did not think enough 'out of the box'., to find this solution by myself  This merits to be documented somewhere, no?

This merits to be documented somewhere, no?

You're right, it should be - It's been a while since I looked at any of our guidance around policy, but I will do some digging to see if we have a CVD for it.

This strategy is definitely used widely.

Roddie

Review Cisco Networking for a $25 gift card