Describes how a shared Layer 3 Out provides external routed connectivity to EPGs in multiple VRFs or tenants through a shared external EPG.
A shared Layer 3 Out is a routed connectivity service that
-
provides external network access to EPGs across VRFs or tenants,
-
controls route sharing and contract-based access through a shared external EPG, and
-
consumes one switch session regardless of the number of consuming EPGs.
Shared Layer 3 Out guidelines and limitations
The following guidelines and limitations apply to shared Layer 3 Out services:
-
Tenant placement: A shared external EPG supports user, common, infra, and mgmt tenants. The external EPG does not have to be in the common tenant.
-
EPG sharing: EPGs in different tenants, bridge domains, or VRFs can share the same external EPG.
-
Subnet scope: Set a subnet to shared to advertise it to consumer or provider EPGs. Set the subnet to public to export it to a Layer 3 Out.
-
Contract management: Export shared-service contracts from the tenant that contains the external EPG, and import the contracts into the consumer tenants.
-
Taboo contracts: A shared Layer 3 Out does not support taboo contracts.
-
Provider support: An external EPG can act as a shared-service provider only when the consumers are nonexternal EPGs.
-
Traffic disruption: Configuring an external EPG with the 0.0.0.0/0 subnet and a shared route-control or shared-security scope triggers a VRF redeployment and interrupts traffic.
-
Prefix uniqueness: External subnet prefixes must be unique within a VRF. Multiple shared Layer 3 Outs with the same prefix in one VRF fail.
-
Traffic restriction: The fabric drops traffic when the scope of an external subnet that is configured for shared route control is a subset of a subnet that is configured for shared security.