The ESG Migration Assistant analyzes and migrates security contract configurations from endpoint groups (EPGs) to endpoint security groups (ESGs) in bulk.
The ESG Migration Assistant is a utility that analyzes the Cisco APIC configuration, generates a migration plan, applies ESG contract configurations, and removes the original EPG contract configurations.
-
Separates security policy configuration on ESGs from network forwarding configuration on EPGs.
-
Supports bulk migration of contract configurations.
-
Supports integration with Cisco Nexus Dashboard.
Migration phases
The ESG Migration Assistant performs migration in three sequential phases.
|
Phase |
Command |
Operation |
|---|---|---|
|
1 |
|
Analyzes the Cisco APIC configuration and generates a YAML migration plan. |
|
2 |
|
Creates the ESG contract configuration defined in the YAML migration plan. |
|
3 |
|
Removes the original contract configuration from the EPGs. |
Migrating security contract configurations to ESGs does not deprecate EPGs. EPGs continue to provide network forwarding functions.
The three phases do not need to be completed during the same maintenance window. Between the
conversionandcleanupphases, the original EPG contracts and the new ESG contracts are active concurrently. This overlap does not disrupt traffic.