Explains L3Out EPG scope, subnet controls, and security import policies, and provides guidance for configuring dynamic ESG and L3Out EPG classification in Cisco ACI environments.
Subnet scope and aggregate controls
Subnet scope and aggregate controls manage route advertisement, security enforcement, and traffic between external and internal endpoint groups.
Static L3Out EPG
A static Layer 3 Outside (L3Out) endpoint group (EPG) uses security-import subnets and contracts to control transit and tenant traffic.
Dynamic ESG and L3Out EPG classification
Dynamic classification updates the policy control tag (pcTag) associated with an external endpoint group or endpoint security group when routing information changes.
DEC guidelines and limitations
Dynamic L3Out EPG Classification has routing-protocol, route-map, topology, and security-configuration requirements.
Configure dynamic ESG and L3Out EPG classification by using the GUI
Configure Dynamic Endpoint Security Group (ESG) Classification and Dynamic L3Out Endpoint Group (EPG) Classification by creating an import route map and assigning an external EPG or ESG based on route matches.