Tenants
A tenant (fvTenant) is a logical container for application policies that enables administrators to implement domain-based access control.
-
Provides policy isolation.
-
Groups policies for customers, organizations, or administrative domains.
-
Supports IPv4, IPv6, and dual-stack network configurations.
Tenant components and configuration
A tenant contains filters, contracts, external networks, bridge domains, VRFs, and application profiles with endpoint groups (EPGs). Objects in a tenant inherit the policies of that tenant.
The following configuration guidelines apply to tenants:
-
Tenants can be isolated from one another or configured to share resources.
-
You must configure a tenant before deploying any Layer 4 through Layer 7 services.
-
You can associate each VRF with multiple bridge domains.
Note |
In the APIC GUI tenant navigation hierarchy, a VRF, also called a context, is labeled as a private network. |
The following figure shows the tenant portion of the management information tree (MIT).


Feedback