Explains Endpoint Security Group concepts and provides guidance for configuring selectors, contracts, route leaking, Layer 4–7 services, migration, and operational tools in Cisco ACI environments.
This chapter contains the following topic:
Endpoint security groups
Endpoint security groups (ESGs) define security zones that can span multiple bridge domains within a single virtual routing and forwarding (VRF) instance.
ESG selectors
Endpoint security group (ESG) selectors classify endpoints by attributes such as policy tags, endpoint group membership, IP subnets, external routes, and service EPGs.
Layer 2 traffic limitations with IP-based selectors
IP-based selectors classify endpoint IP addresses but do not classify MAC addresses used for Layer 2 forwarding and policy enforcement.
Selector precedence
Selector precedence determines which endpoint security group (ESG) classification applies when multiple selectors match the same object.
Contracts for endpoint security groups
Contracts control the traffic that can pass between endpoint security groups (ESGs) and supported Cisco ACI policy objects.
ESG shared services and VRF route leaking
Endpoint security group (ESG) shared services enable communication between endpoints in different virtual routing and forwarding (VRF) instances by separating routing reachability from security policy enforcement.
Layer 4 to Layer 7 services for endpoint security groups
Endpoint security groups (ESGs) support the Layer 4 to Layer 7 service graph features available for endpoint groups (EPGs).
Capacity dashboard
The Capacity Dashboard summarizes fabric-wide and per-leaf resource usage relative to supported scalability limits.
Endpoint tracker
The Endpoint Tracker locates fabric-attached endpoints by IP or MAC address and displays their location, policy-group membership, encapsulation, and transition history.
Endpoint security group guidelines and limitations
Endpoint security group (ESG) configuration has platform, contract, traffic-classification, and feature-interoperability requirements.
EPG-to-ESG migration strategy
Endpoint group (EPG) selectors and contract inheritance support a staged migration from EPG-based security policies to endpoint security group (ESG)-based security policies.
ESG migration assistant
The ESG Migration Assistant analyzes and migrates security contract configurations from endpoint groups (EPGs) to endpoint security groups (ESGs) in bulk.
Create an endpoint security group by using the GUI
Creates an endpoint security group (ESG) and configures its selectors, policy settings, deployment behavior, and contract inheritance.
Apply a contract to an endpoint security group by using the GUI
Associates a provided, consumed, consumed-interface, or intra-ESG contract with an endpoint security group (ESG).
ESG and contract configuration in the REST API
A REST API payload can create an endpoint security group (ESG), associate it with a virtual routing and forwarding (VRF) instance, apply contracts, and configure selectors.
Tags and selectors in the REST API
REST API objects configure tags and selectors that assign endpoint groups (EPGs) or tagged objects to endpoint security groups (ESGs).
Configure route leaking for an internal bridge domain subnet by using the GUI
Leaks an internal bridge domain subnet from a source virtual routing and forwarding (VRF) instance to one or more destination VRF instances.
Route leaking for internal bridge domain subnets in the REST API
A REST API payload can leak an internal bridge domain subnet from a source virtual routing and forwarding (VRF) instance to a destination tenant and VRF instance.
Configure route leaking for external prefixes by using the GUI
Leaks selected external prefixes from a source virtual routing and forwarding (VRF) instance to one or more destination VRF instances.
Route leaking for external prefixes in the REST API
A REST API payload can leak external prefixes from a source virtual routing and forwarding (VRF) instance to a destination tenant and VRF instance.
Configure route leaking for internal prefixes by using the GUI
Leaks selected internal prefixes from a source virtual routing and forwarding (VRF) instance to one or more destination VRF instances.
Apply Layer 4 to Layer 7 services to an endpoint security group by using the GUI
Applies a Layer 4 to Layer 7 service graph template to a contract that is associated with endpoint security groups (ESGs).
Layer 4 to Layer 7 services for endpoint security groups using the REST API
Layer 4 to Layer 7 service graphs can be deployed for endpoint security groups (ESGs) through the REST API.