Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Is it possible to configure a pre-authentication ACL for interfaces configured with wired 802.1x authentication? I would like to have selective network access allowed in the state prior to successful authentication, and then overridden by a dACL gra...
I am trying to give full read-only access to my APICs to an auditor, and I assigned them the "read" permission to the security domain "all" with the cisco-av-pair string "shell:domains=all//admin". However, this does not allow them to see the "Syste...
Hello,I have two logical classes of recipient address: "groupthese" and "dontgroup". If an email is sent to multiple recipents from "groupthese", I would like those to be consolidated down to a single address. It is ok if the address they are conso...
Hello,
From the CLI, I can "show fex 101 detail" and it gives me output, including the FEX description, which is always "FEX0101", or whatever the fex id is. How can I change this description to something more useful, both through the APIC GUI, and ...
Physical domains are associated to EPGs. The APIC "Add Physcal Domain Association" interaction has only three things to set: 1. Physical Domain Profile 2. Deploy Immediacy (Immediate | On Demand) 3. Resolution Immediacy (Immediate | On Dem...
Okay. Is any traffic at all (DHCP / DNS / PXE / etc.) allowed to pass on the switchport prior to authentication? Or is an unauthenticated endpoint completely isolated?
No, you've got it backwards. We cannot control the customer. Them sending it to multiple recipients is already against our wishes. That is why when they do that we want to reduce the number of recipients down to a single one. We want to take many...
Hello Libin,
My use case is this: I work for an eCommerce company, and customers email in orders all the time. Often times customers will send their message to every address they know at my company. We would like to recognize this and deduplicate i...
I think I may have found what we both were looking for. Is the fabric:NodeHealth5min class what you wanted?You can look up the health for each node with a dn path like topology/pod-1/node-101/sys/CDfabricNodeHealth5min, as well as for numerous other...
Thank you, it generally answers my question about the delimiter, but it really does not for the port encap. I do not understand because you also have to specify the port encap for exactly that EPG classification purpose also per static binding. Wha...