Describes intra-EPG endpoint isolation policies that can be applied to directly connected endpoints such as bare metal servers.
Intra-EPG isolation for bare metal servers is a network security mechanism that
-
applies intra-EPG endpoint isolation policies to directly connected endpoints such as bare metal servers
-
enforces isolation at the leaf switch using VLAN encapsulation, and
-
drops all unicast, multicast and broadcast traffic within isolation enforced EPGs.
Key characteristics
Key characteristics of intra-EPG isolation for bare metal servers include the following:
-
Bare metal EPG isolation is enforced at the leaf switch
-
Bare metal servers use VLAN encapsulation
-
All unicast, multicast and broadcast traffic is dropped (denied) within isolation enforced EPGs
-
ACI bridge-domains can have a mix of isolated and regular EPGs
-
Each Isolated EPG can have multiple VLANs where intra-vlan traffic is denied
Use cases
Examples use cases include the following:
-
Backup clients have the same communication requirements for accessing the backup service, buy they don't need to communicate with each other.
-
Servers behind a load balancer have the same communication requirements, but isolating them from each other protects against a server that is compromised or infected.
- Configure intra-EPG isolation for bare metal servers using the GUI
Configure intra-EPG isolation for bare metal servers to prevent communication between endpoints within the same EPG while maintaining external connectivity. - Configure intra-EPG isolation for bare metal servers using the NX-OS style CLI
Configure intra-EPG isolation for bare metal servers to control traffic between endpoints within the same EPG using the NX-OS style CLI.