Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Layer 2 Networking Configuration Guide, Release 6.2(x)

Intra-EPG isolation for bare metal servers

Want to summarize with AI?

Log in

Describes intra-EPG endpoint isolation policies that can be applied to directly connected endpoints such as bare metal servers.


Intra-EPG isolation for bare metal servers is a network security mechanism that

  • applies intra-EPG endpoint isolation policies to directly connected endpoints such as bare metal servers

  • enforces isolation at the leaf switch using VLAN encapsulation, and

  • drops all unicast, multicast and broadcast traffic within isolation enforced EPGs.

Key characteristics

Key characteristics of intra-EPG isolation for bare metal servers include the following:

  • Bare metal EPG isolation is enforced at the leaf switch

  • Bare metal servers use VLAN encapsulation

  • All unicast, multicast and broadcast traffic is dropped (denied) within isolation enforced EPGs

  • ACI bridge-domains can have a mix of isolated and regular EPGs

  • Each Isolated EPG can have multiple VLANs where intra-vlan traffic is denied

Figure 1. Intra-EPG isolation for bare metal servers


Use cases

Examples use cases include the following:

  • Backup clients have the same communication requirements for accessing the backup service, buy they don't need to communicate with each other.

  • Servers behind a load balancer have the same communication requirements, but isolating them from each other protects against a server that is compromised or infected.