Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Apply a contract to an endpoint security group by using the GUI

Want to summarize with AI?

Log in

Associates a provided, consumed, consumed-interface, or intra-ESG contract with an endpoint security group (ESG).


Before you begin

  • Configure the ESG to which you want to apply the contract.

  • Configure the contract or contract interface.

The selected contract relationship determines whether the ESG provides or consumes the contract, consumes a contract interface, or uses the contract to control communication between endpoints in the same ESG.

Procedure

  1. On the menu bar, choose Tenants.

  2. In the Navigation pane, navigate to tenant-name > Application Profiles > application-profile-name > Endpoint Security Groups > esg-name .

  3. Right-click Contracts, and choose the contract relationship to add.

    • Add Provided Contract: Configures the ESG as a provider of the contract.

    • Add Consumed Contract: Configures the ESG as a consumer of the contract.

    • Add Consumed Contract Interface: Configures the ESG to consume a contract through a contract interface.

    • Add Intra-ESG Contract: Applies the contract to communication between endpoints in the ESG.

    Note

    A contract that an application EPG provides or consumes cannot also be applied to an ESG.

  4. In the Add Contract dialog box, configure the contract relationship.

    1. In the Contract Name field, enter or choose the contract.
    2. Optional: In the QOS policy field, choose a quality-of-service policy.
    Note

    Do not configure the Label field. Contract labels are not supported for ESG contract relationships.

  5. Click Submit.

The selected contract relationship is added to the ESG.