Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Endpoint security group guidelines and limitations

Want to summarize with AI?

Log in

Endpoint security group (ESG) configuration has platform, contract, traffic-classification, and feature-interoperability requirements.


ESG guidelines and limitations define the supported policy relationships, deployment environments, and interactions with other Cisco ACI features.

Contract and policy limitations

  • Direct contracts between ESGs and endpoint groups (EPGs), including microsegmented EPGs, are not supported.

  • An ESG contract applies only to routed traffic when the ESG uses an IP-based selector.

  • An intra-ESG contract automatically creates a deny rule and a permit rule. The deny rule enforces intra-ESG isolation even if isolation is not explicitly enabled.

  • Taboo contracts are not supported with ESGs.

  • Contract labels are not supported when contracts are associated with an ESG.

  • An ESG cannot be specified as a source or destination for Switched Port Analyzer (SPAN) traffic.

Platform, topology, and integration requirements

  • ESG deployment requires leaf switches from the -EX generation or later.

  • ESGs are supported in Multi-Tier, Remote Leaf, and Multi-Pod topologies.

  • Beginning with Cisco APIC Release 6.1(4) and Cisco Nexus Dashboard Release 4.1(1), ESGs can be configured through Nexus Dashboard for supported use cases.

  • Policy tags obtained through a virtual machine manager (VMM) integration, such as tags from VMware vCenter, require a full VMM integration. A read-only VMM integration is not sufficient.

Traffic classification through intermediate switches

When endpoints on the same virtual LAN (VLAN) are classified into different ESGs, configure a private VLAN (PVLAN) with isolated ports on any intermediate non-ACI switches. This configuration prevents an intermediate switch from locally switching the traffic before it reaches the Cisco ACI fabric for policy enforcement.

For an EPG associated with a VMware distributed virtual switch (DVS) through VMM integration, enable Allow Micro-Segmentation. This option automatically enables PVLAN behavior on the VMware port group.

Features supported beginning with Release 5.2(3)

Beginning with Cisco APIC Release 5.2(3), ESGs support the following features:

  • Inter-VRF service graphs between ESGs

  • ESG shutdown

  • Host-based routing and host-route advertisement

  • ESGs as a source or destination for On-Demand Atomic Counter

  • ESGs as a source or destination for On-Demand Latency Measurement

Bridge domain and EPG feature interoperability

The following bridge domain and EPG features are supported when their endpoints are classified into an ESG, subject to the specified limitations:

  • Endpoint reachability using static routes on a bridge domain or EPG:

    • The MAC or IP address specified by the feature can be classified into an ESG only through an EPG selector.

    • The static IP address and its next-hop IP address must belong to the same ESG.

  • Anycast service:

    • The MAC or IP address specified by the feature can be classified into an ESG only through an EPG selector.

  • Microsoft Network Load Balancing (NLB):

    • The MAC or IP address specified by the feature can be classified into an ESG only through an EPG selector.

    • To leak the specified IP address to another virtual routing and forwarding (VRF) instance through VRF-level route leaking, explicitly leak its /32 IPv4 or /128 IPv6 route by using route leaking for internal bridge domain subnets. For more information, see Configure route leaking for an internal bridge domain subnet by using the GUI .

  • First-hop security (FHS):

    • FHS is not supported on a microsegmented EPG that is matched to an ESG through an EPG selector.

    • If endpoints must move from a microsegmented EPG to an ESG and still use FHS, classify the endpoints through another selector, such as an IP subnet selector or tag selector. Remove the corresponding match criteria from the microsegmented EPG, and configure FHS on the base EPG.

    • When an EPG is matched to an ESG through an EPG selector, Cisco ACI flushes the FHS binding table and the corresponding endpoints. Traffic does not resume until mechanisms such as Address Resolution Protocol (ARP) or Dynamic Host Configuration Protocol (DHCP) refresh the binding table.

Upgrade consideration for L3Out subnet tags

After upgrading to Cisco ACI Release 6.1(4), remove and re-add any tags on l3extSubnet objects that were configured before the upgrade. ESG tag selectors might not match the existing tags until the tags are re-added.

Local proxy ARP limitations

Beginning with Cisco ACI Release 6.2(3), local proxy ARP can be enabled independently at the bridge domain level. The following limitations apply:

  • Bridge domain-level local proxy ARP and EPG-level proxy ARP are mutually exclusive. This restriction includes intra-EPG isolation with proxy ARP.

  • Local proxy ARP cannot be enabled on a bridge domain that contains an EPG with an intra-EPG contract. An intra-EPG contract cannot be configured on an EPG whose bridge domain has local proxy ARP enabled.

  • Flood in Encapsulation (FIE) cannot be used with local proxy ARP, regardless of whether FIE is configured at the bridge domain or EPG level.

  • Local proxy ARP is supported on all switch platforms except the N9K-C93180LC-EX.

  • Local proxy ARP is supported in Multi-Pod, Remote Leaf, NDO Multi-Site, and BGW Multi-Site topologies.

  • Local proxy ARP is not supported in a mixed-mode fabric in which some leaf switches run a release earlier than 6.2(3) and other leaf switches run Release 6.2(3) or later. Cisco APIC raises a fault but does not block the configuration.

Intra-EPG traffic enforcement

Note

An intra-EPG contract with a permit-all rule and intra-EPG isolation with proxy ARP both cause traffic to be routed through Cisco ACI leaf switches. An intra-EPG contract enables proxy ARP implicitly.

With an intra-EPG contract that contains a permit-all rule, endpoints that do not belong to an ESG can continue to communicate within the same EPG. With intra-EPG isolation and proxy ARP, those endpoints cannot communicate with each other, even when they belong to the same EPG.

Microsegmentation deployment behavior

When Allow Micro-Segmentation is enabled, Cisco APIC ignores the Resolution Immediacy setting in the VMM domain association to the EPG.

The resulting behavior combines On Demand and Immediate deployment. After at least one virtual machine is attached to the EPG VLAN, Cisco APIC deploys the VLAN on all Cisco ACI switch interfaces connected to hypervisor hosts that use the VMM-integrated virtual switch.