Configure Dynamic Endpoint Security Group (ESG) Classification and Dynamic L3Out Endpoint Group (EPG) Classification by creating an import route map and assigning an external EPG or ESG based on route matches.
Before you begin
-
Create the tenant, private network, and bridge domain.
-
Create the Layer 3 Outside (L3Out) connection for the tenant network.
This procedure assumes that the L3Out uses Border Gateway Protocol (BGP). You can also use this procedure for an L3Out that uses Open Shortest Path First (OSPF).
Import route control is not enforced by default. You must explicitly enable import route-control enforcement.
Procedure
| 1. | On the menu bar, choose . |
|
| 2. | In the Work pane, double-click the tenant name. |
|
| 3. | In the Navigation pane, choose . |
|
| 4. | Right-click l3out_name and choose Create Route map for import and export route control . |
|
| 5. | In the Create Route map for import and export route control dialog box, configure the route map: |
|
| 6. | In the Create Route Control Context dialog box, configure the route-control context: |
|
| 7. | In the Work pane, choose the tabs. The Properties appear in the Work pane. |
|
| 8. | Next to Route Control Enforcement , check the Import check box, and click Submit . Import route-control enforcement is disabled by default. It is supported for BGP and OSPF but not for Enhanced Interior Gateway Routing Protocol (EIGRP). If you enable import route-control enforcement for an unsupported protocol, the policy is ignored for that protocol. Export route control is supported for BGP, EIGRP, and OSPF. You do not need to check the Import check box when you configure a BGP per-neighbor import route map.
|