cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
438
Views
0
Helpful
1
Replies

ACI contract confusion

JPC113
Level 1
Level 1

Hi,

I have configured a contract to operate between a couple of EPGs which is working as expected, however, I have a PC within one of the EPGs that I can access via RDP and I am not sure why.  The source sits on our LAN and connects through a L3 Out into the ACI network.

The simplified diagram looks like below 

JPC113_1-1695131731170.png

 

 

The contract rules are below

RuleEthertypeIP ProtocolSource / RangeDetination From Destination to
1IPTCPUnspecified6148361483
2IPTCPUnspecified6148461484
3IPUDPUnspecified123123
4IPTCPUnspecified123123
5IPUDPUnspecified323323
6IPTCPUnspecified323323
7IPTCPUnspecifiedSSHSSH
8IPTCPUnspecified3276861000
9IPTCPUnspecified50205020

The connection starts from 192.168.76.31 source port XXXX destination IP 192.168.129.209 destination port 3389.  The destination port is not listed in the table above yet 3389 is allowed through.  If I remove entry number 8 then RDP is denied but TCP 3389 is not listed here.

I presume that I'm missing something blatantly obvious here.

thanks for any help

 

Jon

1 Accepted Solution

Accepted Solutions

JPC113
Level 1
Level 1

This is now working as expected.  The filter previously had an RDP entry in it which had been deleted so I wondered even though it had been deleted if it was actually hiding somewhere in the background having fun at my expense.  I deleted the filter, created a new one and now its working ok.

 

 

deleted the filter and created a new one an 

View solution in original post

1 Reply 1

JPC113
Level 1
Level 1

This is now working as expected.  The filter previously had an RDP entry in it which had been deleted so I wondered even though it had been deleted if it was actually hiding somewhere in the background having fun at my expense.  I deleted the filter, created a new one and now its working ok.

 

 

deleted the filter and created a new one an 

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License