Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure route leaking for internal prefixes by using the GUI

Want to summarize with AI?

Log in

Leaks selected internal prefixes from a source virtual routing and forwarding (VRF) instance to one or more destination VRF instances.


Before you begin

Complete one of the following configurations:

  • Configure the tenant, source VRF instance, bridge domain, and subnet to leak.

  • Configure a border gateway (BGW) and verify that the source VRF instance has learned the internal Ethernet VPN (EVPN) Type 5 prefixes from another fabric.

Configure the destination tenant and VRF instances.

Internal prefix route leaking uses IP prefix-list-style matching. You can leak a specific prefix or use minimum and maximum prefix lengths to match a range of prefixes.

Route leaking provides routing reachability only. Configure the required endpoint security group (ESG) contract relationships separately to permit traffic between VRF instances.

Procedure

  1. In the Navigation pane, navigate to Tenants > tenant-name > Networking > VRFs > source-vrf-name > Inter-VRF Leaked Routes for ESG > Internal Prefixes .

  2. Right-click Internal Prefixes, and choose Create Leaked Internal Prefix.

  3. In the Create Leaked Internal Prefix dialog box, configure the prefix match.

    1. In the IP field, enter the internal prefix to leak.
    2. Optional: In the Description field, enter a description of the leaked internal prefix.
    3. Optional: In the Greater than or Equal (Prefix) field, enter the minimum prefix length to match.

      This value is equivalent to the ge option in an IP prefix list.

    4. Optional: In the Less than or Equal (Prefix) field, enter the maximum prefix length to match.

      This value is equivalent to the le option in an IP prefix list.

  4. In the Tenant and VRF destinations field, click +.

  5. In the Create Tenant and VRF destination dialog box, configure the destination.

    1. In the Tenant and VRF field, choose the destination tenant and VRF instance.
    2. Optional: In the Description field, enter a description of the destination.
    3. Click OK.
  6. Click Submit.

The internal prefixes that match the configured prefix criteria are leaked to the selected destination VRF instances.