Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure route leaking for an internal bridge domain subnet by using the GUI

Want to summarize with AI?

Log in

Leaks an internal bridge domain subnet from a source virtual routing and forwarding (VRF) instance to one or more destination VRF instances.


Before you begin

Configure the tenant, source and destination VRF instances, bridge domain, and subnet to leak.

VRF-level route leaking provides routing reachability for the specified bridge domain subnet. Configure the required contract relationships separately to permit traffic between endpoint security groups (ESGs) in different VRF instances.

Procedure

  1. In the Navigation pane, navigate to Tenants > tenant-name > Networking > VRFs > source-vrf-name > Inter-VRF Leaked Routes for ESG > EPG/BD Subnets .

  2. Right-click EPG/BD Subnets, and choose Configure EPG/BD Subnet to leak.

  3. In the Configure EPG/BD Subnet to leak dialog box, configure the subnet.

    1. In the IP field, enter the bridge domain subnet and prefix length to leak.
    2. Optional: In the Description field, enter a description of the leaked subnet.
    3. Optional: Set Allow L3Out Advertisement to True if Layer 3 Outside (L3Out) connections in the destination VRF instances must advertise the leaked subnet.
  4. In the Tenant and VRF destinations field, click +.

  5. In the Create Tenant and VRF destination dialog box, configure the destination.

    1. In the Tenant and VRF field, choose the destination tenant and VRF instance.
    2. Optional: In the Description field, enter a description of the destination.
    3. For Allow L3Out Advertisement, choose the advertisement behavior for this destination VRF instance.
      • True: Allows L3Out connections in this destination VRF instance to advertise the leaked subnet.

      • False: Prevents L3Out connections in this destination VRF instance from advertising the leaked subnet.

      • inherit (default): Uses the Allow L3Out Advertisement value configured for the leaked subnet.

    4. Click OK.
  6. Click Submit.

The internal bridge domain subnet is leaked to the selected destination VRF instances with the configured L3Out advertisement behavior.