Describes subnet scope and aggregate controls that manage route advertisement, route sharing, security-policy enforcement, and prefix aggregation for external EPGs and L3Outs.
Subnet scope and aggregate controls are configuration settings that
-
control route advertisement into and out of the fabric,
-
define security requirements for traffic between external and internal EPGs, and
-
aggregate prefixes for route-control policies.
Subnet control options
The following options control subnet behavior:
-
Export Route Control Subnet: Advertises specific transit routes out of the fabric. This option does not control internal routes or bridge domain default gateways.
-
Import Route Control Subnet: Advertises BGP and OSPF routes into the fabric when import route-control enforcement is configured.
-
External Subnets for the External EPG (Security Import Subnet): Permits traffic between external EPGs or between external and internal EPGs. This option requires a contract and a security prefix.
-
Shared Route Control Subnet: Marks routes that are learned from a shared L3Out for advertisement to other VRFs during inter-VRF route leaking.
-
Shared Security Import Subnet: Provides the same security behavior as External Subnets for the External EPG for routes that are learned from shared L3Outs.
-
Aggregate Export, Aggregate Import, and Aggregate Shared Routes: Add the value 32 before the
0.0.0.0/0prefix and restrict route-control profiles to the0.0.0.0/0network. -
Aggregate Shared Route: This option is available for any prefix that is marked as a Shared Route Control Subnet.
-
Route Control Profile: This profile supports route-map set clauses for routes that are advertised into and out of the fabric. Configure the clauses through route-control profile policies and action-rule profiles.