Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Configure first-hop security using the Cisco APIC GUI

Want to summarize with AI?

Log in

Configures First-Hop Security and trust control policies in the Cisco APIC GUI and applies them to an endpoint group and bridge domain.


Use this procedure to create a First-Hop Security feature policy and a trust control policy, and then apply the policies to an endpoint group and bridge domain.

Before you begin

Configure the tenant and bridge domain.

Procedure

  1. Create a First-Hop Security policy.

    1. On the menu bar, choose Tenants > tenant-name.
    2. In the Navigation pane, expand Policies > Protocol > First Hop Security.
    3. Right-click First Hop Security and choose Create Feature Policy.
    4. In the Name field, enter a name for the policy.
    5. Enable IP Inspection, Source Guard, and Router Advertisement, and then click Submit.
  2. Create a trust control policy.

    1. In the Navigation pane, expand First Hop Security.
    2. Right-click Trust Control Policies and choose Create Trust Control Policy.
    3. In the Name field, enter a name for the policy.
    4. Select the features that the policy allows, and then click Submit.
  3. Apply the trust control policy to an endpoint group (EPG).

    1. In the Navigation pane, expand Application Profiles > application-profile-name > Application EPGs, and then choose application-EPG-name.
    2. In the Work pane, click the General tab.
    3. From the FHS Trust Control Policy drop-down list, choose the trust control policy that you created, and then click Submit.
  4. Apply the First-Hop Security policy to the bridge domain.

    1. In the Navigation pane, expand Bridge Domains > bridge-domain-name.
    2. Click the Advanced/Troubleshooting tab.
    3. From the First Hop Security Policy drop-down list, choose the policy that you created, and then click Submit.

    First-Hop Security is configured for the bridge domain.