Describes the most important object in the policy model and its relationship to other objects in the tenant.
An endpoint group (EPG) is a managed object that
-
contains a collection of endpoints with common policy requirements such as security, virtual machine mobility (VMM), QoS, or Layer 4 to Layer 7 services
-
is fully decoupled from the physical and logical topology, and
-
enables centralized policy management for groups of endpoints rather than individual endpoint configuration.
The following figure shows where application EPGs are located in the management information tree (MIT) and their relation to other objects in the tenant.
Endpoints are devices that are connected to the network directly or indirectly. They have an address (identity), a location, attributes (such as version or patch level), and can be physical or virtual. Knowing the address of an endpoint also enables access to all its other identity details. Endpoint examples include servers, virtual machines, network-attached storage, or clients on the Internet. Endpoint membership in an EPG can be dynamic or static.
The ACI fabric can contain the following types of EPGs:
-
Application endpoint group (
fvAEPg) -
Layer 2 external outside network instance endpoint group (
l2extInstP) -
Layer 3 external outside network instance endpoint group (
l3extInstP) -
Management endpoint groups for out-of-band (
mgmtOoB) or in-band (mgmtInB) access.
Policies apply to EPGs, never to individual endpoints. An EPG can be statically configured by an administrator in the APIC, or dynamically configured by an automated system such as vCenter or OpenStack.
When an EPG uses a static binding path, the encapsulation VLAN associated with this EPG must be part of a static VLAN pool. For IPv4/IPv6 dual-stack configurations, the IP address property is contained in the fvStIpchild property of thefvStCEpMO. MultiplefvStIpobjects supporting IPv4 and IPv6 addresses can be added under onefvStCEpobject. When upgrading ACI from IPv4-only firmware to versions of firmware that support IPv6, the existing IP property is copied to anfvStIpMO.
Regardless of how an EPG is configured, EPG policies are applied to the endpoints they contain.
If a leaf switch is configured for static binding (leaf switches) under an EPG, the following restrictions apply:
The static binding cannot be overridden with a static path.
Interfaces in that switch cannot be used for routed external network (L3out) configurations.
Interfaces in that switch cannot be assigned IP addresses.
Static and dynamic EPG configuration examples
WAN router connectivity to the fabric is an example of a configuration that uses a static EPG. To configure WAN router connectivity to the fabric, an administrator configures an l3extInstP EPG that includes any endpoints within an associated WAN subnet. The fabric learns of the EPG endpoints through a discovery process as the endpoints progress through their connectivity life cycle. Upon learning of the endpoint, the fabric applies the l3extInstP EPG policies accordingly. For example, when a WAN connected client initiates a TCP session with a server within an application (fvAEPg) EPG, the l3extInstP EPG applies its policies to that client endpoint before the communication with the fvAEPg EPG web server begins. When the client server TCP session ends and communication between the client and server terminate, that endpoint no longer exists in the fabric.
Virtual machine management connectivity to VMware vCenter is an example of a configuration that uses a dynamic EPG. Once the virtual machine management domain is configured in the fabric, vCenter triggers the dynamic configuration of EPGs that enable virtual machine endpoints to start up, move, and shut down as needed.