Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Configure intra-EPG isolation for bare metal servers using the GUI

Want to summarize with AI?

Log in

Configure intra-EPG isolation for bare metal servers to prevent communication between endpoints within the same EPG while maintaining external connectivity.


The port the EPG uses must be associated with a bare metal server interface in the physical domain that is used to connect the bare metal servers directly to leaf switches.

Procedure

  1. In a tenant, right click on an Application Profile, and open the Create Application EPG dialog box to perform the following actions:

    1. In the Name field, add the EPG name (intra_EPG-deny).
    2. For Intra EPG Isolation, click Enforced.
    3. In the Bridge Domain field, choose the bridge domain from the drop-down list (bd1).
    4. Check the Statically Link with Leaves/Paths check box.
    5. Click Next.
  2. In the Leaves/Paths dialog box, perform the following actions:

    1. In the Path section, choose a path from the drop-down list (Node-107/eth1/16) in Trunk Mode.

      Specify the Port Encap (vlan-102) for the secondary VLAN.

      Note

      If the bare metal server is directly connected to a leaf switch, only the Port Encap secondary VLAN is specified.

      Specify the Primary Encap (vlan-103) for the primary VLAN.

    2. Click Update.
    3. Click Finish.