Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Contracts for endpoint security groups

Want to summarize with AI?

Log in

Contracts control the traffic that can pass between endpoint security groups (ESGs) and supported Cisco ACI policy objects.


A contract is a policy construct that specifies the protocols and ports permitted between ESGs or between an ESG and another supported policy object.

  • An ESG can provide contracts, consume contracts, or both.

  • An ESG can consume multiple contracts.

  • ESGs included in a preferred group can communicate without contracts.

Supported contract relationships

ESGs support contracts in the following relationships:

  • ESG to ESG

  • ESG to Layer 3 Outside (L3Out) external EPG

  • ESG to in-band EPG

  • ESG to vzAny

Contract features and limitations

  • Contracts between ESGs and application EPGs or microsegmented EPGs are not supported.

  • To enable communication between an ESG endpoint and application EPG endpoints, migrate the application EPG endpoints to ESGs.

  • During migration, you can use vzAny or a preferred group to enable communication.

  • ESGs support contract inheritance, intra-ESG contracts, and intra-ESG isolation.

  • ESGs do not support taboo contracts.


vzAny

The vzAny construct represents all EPGs and ESGs within a VRF instance.

  • Includes application EPGs, ESGs, and Layer 3 Outside (L3Out) external EPGs.

  • Provides a single point at which to configure contracts for multiple EPGs and ESGs.

  • Can reduce hardware resource consumption compared with configuring equivalent contracts separately for individual EPGs and ESGs.

Contract behavior

You can use vzAny as a contract provider, consumer, or both.

  • A contract between vzAny and a specific EPG or ESG controls communication between that object and the other EPGs and ESGs in the VRF instance.

  • To enable any-to-any communication within the VRF instance, configure vzAny to provide and consume a contract that permits all required traffic.

  • The contract filters and provider-consumer relationships determine which traffic is permitted.

Contract application methods

Characteristic

Individual contracts

vzAny contract

Configuration scope

Specific EPGs or ESGs

All EPGs and ESGs in the VRF instance

Hardware resource use

May require separate policy rules for each relationship

Can reduce policy-rule duplication by applying a contract collectively

Note

In a VRF route-leaking configuration, a scenario in which ESGs use vzAny between two consumers is not supported. The ESG in the second VRF instance does not become a preferred-group member, and Cisco APIC raises a fault.

The following figure illustrates how vzAny represents all EPGs and ESGs in the same VRF instance.

Figure 1. EPGs and ESGs represented by vzAny

Contract between vzAny and an EPG

For example, a contract between vzAny and EPG4-1 permits endpoints 192.168.1.11 and 192.168.2.11 in ESG1, and endpoint 192.168.3.11 in EPG3-1, to communicate with endpoint 192.168.4.11 in EPG4-1 as allowed by the contract.


Preferred groups

A preferred group is a policy construct that permits communication among its members without requiring explicit contracts or vzAny contracts.

  • Endpoints associated with preferred-group members can communicate with each other without contracts.

  • ESGs, application EPGs, and external EPGs in the same VRF instance can be included in the preferred group.

  • A preferred group can support migration from EPG-based security policies to ESG-based security policies.

Communication behavior

  • ESGs included in the preferred group can communicate with other included ESGs.

  • An included ESG can communicate with included application EPGs and external EPGs.

  • Communication with an object that is excluded from the preferred group requires a supported contract relationship.

  • Direct contracts between ESGs and application EPGs are not supported.

Migration example

  1. ESG1 and EPG3-1 can communicate because both objects are included in the preferred group.

  2. ESG1 and EPG4-1 cannot communicate because EPG4-1 is excluded from the preferred group and direct contracts between ESGs and application EPGs are not supported.

Figure 2. ESG1 and EPG3-1 in the same preferred group

For preferred-group configuration information, see the Cisco APIC Basic Configuration Guide .