Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Apply Layer 4 to Layer 7 services to an endpoint security group by using the GUI

Want to summarize with AI?

Log in

Applies a Layer 4 to Layer 7 service graph template to a contract that is associated with endpoint security groups (ESGs).


Before you begin

Configure the following objects:

  • The ESGs to which you want to apply the service graph.

  • A Layer 4 to Layer 7 service graph template.

The service graph configurations available for endpoint groups (EPGs) also apply to ESGs. For an ESG deployment, associate the contract with the ESGs instead of the EPGs. Use this procedure to apply a service graph template for an unmanaged Layer 4 to Layer 7 service device to a contract that is associated with ESGs.

Procedure

  1. On the menu bar, choose Tenants > All Tenants .

  2. In the Work pane, double-click the tenant-name .

  3. In the Navigation pane, expand tenant-name > Services > L4-L7 > Service Graph Templates .

  4. Right-click the service-graph-template-name and choose Apply L4-L7 Service Graph Template .

    The Apply L4-L7 Service Graph Template To EPGs dialog box appears.

  5. On the STEP 1 > Contract page, configure the contract.

    1. For the endpoint group type, choose Endpoint Security Group .
    2. For an intra-ESG contract, select Configure an Intra-Endpoint Contract and choose the ESG from ESG / Network .
    3. For a contract between ESGs, choose the consumer and provider ESG and network combinations.
    4. In the Contract Type field, create a contract or choose an existing contract.

      To configure filters for a new contract, clear No Filter (Allow All Traffic) , click the + icon, configure the filters, and click Update .

      Note

      To configure a contract between an ESG and vzAny , choose AnyEPG for the provider and the ESG for the consumer, or choose the ESG for the provider and AnyEPG for the consumer.

      To apply a service graph to a vzAny -to- vzAny contract, choose Endpoint Policy Group (EPG) as the endpoint group type and choose AnyEPG for both the provider and consumer.

  6. Click Next .

    The STEP 2 > Graph page appears.

  7. In the device-name Information section, configure the required fields.

  8. Click Finish .

The service graph template is applied to the contract that is associated with the selected ESGs.