Explains intra-EPG endpoint isolation policies that provide full isolation for virtual or physical endpoints within an EPG.
Intra-EPG endpoint isolation is a policy that
-
provides full isolation for virtual or physical endpoints within an EPG
-
prevents communication between endpoints in an EPG that is operating with isolation enforced, and
-
reduces the number of EPG encapsulations required when many clients access a common service but are not allowed to communicate with each other.
Isolation enforcement characteristics
An EPG is isolation enforced for all Cisco Application Centric Infrastructure (ACI) network domains or none. While the Cisco ACI fabric implements isolation directly to connected endpoints, switches connected to the fabric are made aware of isolation rules according to a primary VLAN (PVLAN) tag.
If an EPG is configured with intra-EPG endpoint isolation enforced, these restrictions apply:
All Layer 2 endpoint communication across an isolation enforced EPG is dropped within a bridge domain.
All Layer 3 endpoint communication across an isolation enforced EPG is dropped within the same subnet.
Preserving QoS CoS priority settings is not supported when traffic is flowing from an EPG with isolation enforced to an EPG without isolation enforced.
BPDUs are not forwarded through EPGs with intra-EPG isolation enabled. Therefore, when you connect an external Layer 2 network that runs spanning tree in a VLAN that maps to an isolated EPG on Cisco ACI, Cisco ACI might prevent spanning tree in the external network from detecting a Layer 2 loop. You can avoid this issue by ensuring that there is only a single logical link between Cisco ACI and the external network in these VLANs.