Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

EPG-to-ESG migration strategy

Want to summarize with AI?

Log in

Endpoint group (EPG) selectors and contract inheritance support a staged migration from EPG-based security policies to endpoint security group (ESG)-based security policies.


An EPG-to-ESG migration uses an EPG selector to assign an existing EPG to an ESG. The ESG temporarily inherits the contracts associated with the EPG so that existing contract relationships remain available during the migration.

  • EPG selectors enable an ESG to inherit contracts from a matched EPG.

  • Contract inheritance supports communication while endpoints and contract relationships are migrated.

  • Matching an EPG to an ESG changes its policy control tag (pcTag) and can cause a brief traffic disruption.

Migration sequence

  1. Identify the EPG to migrate, and review its provider and consumer contract relationships.

  2. Create an ESG, and use an EPG selector to match the EPG to the ESG.

  3. Verify that the ESG inherits the expected contracts and that endpoint communication continues as expected.

  4. Configure any additional contracts required between ESGs or between an ESG and a Layer 3 Outside (L3Out) external EPG.

  5. Create additional ESGs, and migrate the remaining EPGs by using EPG selectors.

  6. Create replacement ESG contracts that use the same filters as the original EPG contracts.

  7. Assign the required provider and consumer relationships to the ESGs, and verify communication.

  8. Remove the legacy EPG provider and consumer relationships from the original contracts.

  9. Repeat the process for each remaining contract relationship.

Figure 1. Prepare for EPG-to-ESG migration
Figure 2. Create an ESG and migrate the first EPG
Figure 3. Create additional ESGs and migrate the remaining EPGs
Figure 4. Create a replacement contract
Figure 5. Remove the EPG provider relationship from the original contract

Migration considerations

  • If an EPG subnet is used for endpoint classification, migrate the EPG to an ESG by using an EPG selector, and then remove the EPG subnet classification.

  • For an inter-VRF ESG migration, configure route leaking before configuring the ESG relationships.

  • For inter-VRF contracts between vzAny and an EPG, ESG, or L3Out external EPG, review the contract actions and placement of the service-device connectors before migration.

Note

Before migrating an L3Out external EPG to an ESG, delete the existing contracts associated with the external EPG.

Migrate EPGs that use a shared contract

EPG A1 initially provides contract C1 to EPGs B1, B2, and B3. After EPG A1 is matched to ESG A1, ESG A1 inherits contract C1, allowing the existing communication to continue during migration. After EPGs B1, B2, and B3 are migrated to ESGs, create a replacement contract with the same filters and configure the ESG provider and consumer relationships. After verifying communication, remove the original EPG contract relationships.