Configure Dynamic Endpoint Security Group (ESG) Classification and Dynamic L3Out Endpoint Group (EPG) Classification by creating an import route map and assigning an external EPG or ESG based on route matches.
Before you begin
-
Create the tenant, private network, and bridge domain.
-
Create the Layer 3 Outside (L3Out) connection for the tenant network.
This procedure assumes that the L3Out uses Border Gateway Protocol (BGP). You can also use this procedure for an L3Out that uses Open Shortest Path First (OSPF).
Import route control is not enforced by default. You must explicitly enable import route-control enforcement.