Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Configure intra-EPG isolation for bare metal servers using the NX-OS style CLI

Want to summarize with AI?

Log in

Configure intra-EPG isolation for bare metal servers to control traffic between endpoints within the same EPG using the NX-OS style CLI.


Procedure

  1. In the CLI, create an intra-EPG isolation EPG:

    Example:

    The VMM case is below.
    ifav19-ifc1(config)# tenant Test_Isolation  
    ifav19-ifc1(config-tenant)# application PVLAN 
    ifav19-ifc1(config-tenant-app)# epg EPG1 
    ifav19-ifc1(config-tenant-app-epg)# show running-config  
    # Command: show running-config 
    tenant Test_Isolation
     application PVLAN epg EPG1   
      tenant Test_Isolation
         application PVLAN 
          epg EPG1 
            bridge-domain member BD1
            contract consumer bare-metal
            contract consumer default
            contract provider Isolate_EPG 
            isolation enforce   <---- This enables EPG isolation mode.
            exit
        exit
    ifav19-ifc1(config)# leaf ifav19-leaf3
    ifav19-ifc1(config-leaf)# interface ethernet 1/16
    ifav19-ifc1(config-leaf-if)# show running-config 
    ifav19-ifc1(config-leaf-if)# switchport trunk native vlan 101 tenant Test_Isolation application PVLAN epg StaticEPG primary-vlan 100
    exit
  2. Verify the configuration:

    Example:

    show epg StaticEPG detail
    Application EPg Data: 
    Tenant              : Test_Isolation 
    Application         : PVLAN 
    AEPg                : StaticEPG 
    BD                  : BD1 
    uSeg EPG            : no 
    Intra EPG Isolation : enforced 
    Vlan Domains        : phys 
    Consumed Contracts  : bare-metal 
    Provided Contracts  : default,Isolate_EPG 
    Denied Contracts    :  
    Qos Class           : unspecified 
    Tag List            :   
    VMM Domains: 
    Domain                Type       Deployment Immediacy  Resolution Immediacy  State           Encap       Primary 
    Encap  
     --------------------  ---------  --------------------  --------------------  --------------  ----------  ----------     
     DVS1                  VMware     On Demand             immediate             formed          auto        auto           
     
    Static Leaves: 
     Node        Encap             Deployment Immediacy  Mode                Modification Time                
    ----------  ----------------  --------------------  ------------------  ------------------------------  
     
    Static Paths: 
     Node        Interface                       Encap             Modification Time               
     ----------  ------------------------------  ----------------  ------------------------------  
     1018        eth101/1/1                      vlan-100          2016-02-11T18:39:02.337-08:00    
     1019        eth1/16                         vlan-101          2016-02-11T18:39:02.337-08:00   
     
    Static Endpoints: 
     Node        Interface          Encap             End Point MAC      End Point IP Address          Modification Time               
     ----------  ------------------------------  ----------------  -----------------  ------------------------------  ------------------------------