Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

First-hop security guidelines and limitations

Want to summarize with AI?

Log in

Lists the deployment restrictions, endpoint-binding behavior, traffic effects, and virtual machine manager domain requirements that apply to first-hop security in Cisco ACI.


Review these guidelines and limitations before you enable first-hop security in Cisco ACI.

First-hop security guidelines and limitations

These guidelines and limitations apply to first-hop security:

  • When the front-panel port on which a secured endpoint was learned goes down, the endpoint entry in the first-hop security (FHS) binding table enters the DOWN state. The system removes the entry after 18 hours. If the endpoint appears on another port during this period and is reachable through that port, the system moves the entry to the new location and changes its state to REACHABLE or STALE.

  • IP Source Guard does not enforce source MAC address-to-source IP address bindings for traffic that uses an IPv6 link-local source address. The system permits this traffic even if a binding check fails.

  • FHS is not supported on L3Out interfaces.

  • FHS is not supported on top-of-rack switches that use the N9K-M12PQ platform.

  • FHS in Cisco ACI Multi-Site is a site-local capability and must be enabled from the Cisco APIC cluster at each site. FHS is supported only when the bridge domain (BD) and endpoint group (EPG) are site-local. FHS is not supported on stretched BDs or EPGs.

  • FHS is not supported on a Layer 2-only BD.

  • Enabling FHS can disrupt traffic for 50 seconds because the system flushes the endpoints in the BD and disables endpoint learning in the BD during that period.

  • FHS is not supported on microsegmented (uSeg) EPGs that are matched to an endpoint security group (ESG) by using EPG selectors. To use FHS for endpoints that move from a uSeg EPG to an ESG, classify the endpoints by using another selector, such as an IP subnet or tag selector. Remove the matching criteria from the uSeg EPG, and configure FHS on the base EPG.

  • When an EPG is matched to an ESG by using an EPG selector, the system flushes the FHS binding table and the corresponding endpoints. Traffic is unavailable until ARP, DHCP, or another protocol refreshes the binding table.

Virtual machine manager domain guidelines

For virtual machine manager (VMM) domains, apply these requirements:

  • Deploy an EPG that is attached to a VMM domain with the resolution immediacy set to Immediate or Pre-provision.

  • Enable ARP flooding on the BD.

  • Enabling IP Source Guard can affect first-hop redundancy protocols (FHRPs), such as Virtual Router Redundancy Protocol (VRRP), because the source IP address and MAC address of control packets can differ from the binding in the FHS binding table.