Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

First-hop security policy deployment

Want to summarize with AI?

Log in

Describes how first-hop security policies define feature behavior, apply to tenant bridge domains or endpoint groups, and resolve overlapping policy assignments.


Use this reference to understand how first-hop security policies are defined, applied, and selected in Cisco ACI.

First-hop security policy assignment

Most first-hop security (FHS) features use this two-stage configuration process:

  1. Define a policy that specifies the behavior of the feature.

  2. Apply the policy to a domain, such as a tenant bridge domain or tenant endpoint group (EPG).

You can apply policies with different behaviors to domains that intersect. When multiple policies apply, the system uses the policy assigned to the most specific domain.

In the Cisco APIC GUI, configure the policy options at tenant-name > Networking > Protocol Policies > First Hop Security.