Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Restricting access by domains

Want to summarize with AI?

Log in

Describes how security domains enable fabric administrators to control user access to Cisco ACI resources. Provides context for multi-tenancy and resource separation in complex environments.


Security domains are logical groupings that allow fabric administrators to selectively expose resources to specific users and assign permissions for reading and modifying those resources.

  • Enable separation of management access for different user groups.

  • Support multi-tenancy by isolating resources and access policies.

  • Allow configuration of restricted domains to prevent cross-domain visibility and modification.

Security Domain Restriction and Multi-Tenancy

Starting with Cisco APIC (Fabric Controller) release 5.0(1), administrators can configure security domains as "Restricted." This prevents users in one domain from viewing or modifying objects created by users in another domain, even if privileges are the same.

  • Restricted domains prevent cross-domain access.

  • Users always have read-only visibility to system-created configurations if privileges allow.

  • Administrators can assign broad privileges within a restricted domain without risking impact to other tenants.

To configure restricted security domains, follow these steps:

  1. Identify the user groups requiring separation.

  2. Assign users to appropriate security domains.

  3. Set the domain as "Restricted" in Cisco APIC.

Access policies outside the tenant level can leverage restricted domains for enhanced multi-tenancy:

  • Each tenant can create access policies hidden from other tenants by using separated restricted domains.

Figure 1. Restricted Security Domains

Restricted Security Domain Example

For example, a user associated with restricted security domain domainA cannot see policies, profiles, or users configured by users associated with security domain domainB . Users associated with domainB can see policies, profiles, or users configured by users associated with domainA , unless domainB is also configured as restricted.