Route leaking for external prefixes exports routes from an L3Out in one VRF instance to another VRF instance. This configuration is referred to as an ESG shared L3Out to distinguish it from an EPG shared L3Out.
-
Route leaking is configured at the VRF level independently of ESG contracts.
-
An IP prefix-list-style configuration identifies the external prefixes to leak.
-
The configuration identifies the target VRF instance and the policy object that supplies the security classification.
External prefix matching
You can specify an individual external prefix or a range of external prefixes.
-
Use the le or ge option to match a range of prefix lengths.
-
External prefix matching does not impose restrictions on the prefix size.
-
Unlike route leaking for bridge domain subnets, one external prefix configuration can match and leak multiple prefixes.
L3Out security options
Select one of the following methods to provide security classification for the leaked external prefixes:
|
Security method
|
Required configuration
|
Contract relationship
|
|
Use the L3Out external EPG without assigning its subnets to an ESG.
|
Configure the applicable L3Out subnets with the External Subnets for the External EPG and Shared Security Import Subnet scopes.
|
Configure a contract between the L3Out external EPG in one VRF instance and the ESG in the other VRF instance.
|
|
Use an ESG with an External EPG Selector that matches the L3Out external EPG.
|
Configure the applicable L3Out subnets with the External Subnets for the External EPG and Shared Security Import Subnet scopes.
|
Configure a contract between the ESGs in the two VRF instances.
|
|
Use an ESG with a Tag Selector that matches specific L3Out subnets under the external EPG.
|
Configure the applicable L3Out subnets with the External Subnets for the External EPG and Shared Security Import Subnet scopes.
|
Configure a contract between the ESGs in the two VRF instances.
|
|
Use an ESG with an External Subnet Selector that matches specific external prefixes.
|
Enable the Shared option on the External Subnet Selector. L3Out subnet configuration under the external EPG is not required for security classification.
|
Configure a contract between the ESGs in the two VRF instances.
|
Advertisement from the target VRF instance
Before Cisco APIC Release 6.1(4), the Shared Route Control Subnet option was required to advertise a leaked route through another L3Out.
Beginning with Cisco APIC Release 6.1(4), the Shared Route Control Subnet option is not used for ESGs. External prefix configuration controls route leaking.
Note
Leaked external prefixes are not advertised through an L3Out in the target VRF instance by default. Configure an explicit route map to advertise them.
For configuration instructions, see Configure route leaking for external prefixes by using the GUI .