Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

What's changed in this guide

Want to summarize with AI?

Log in

Summarizes significant changes and new features in this guide for recent Cisco APIC releases and identifies the related documentation.


Review the new features and changed behavior documented for recent Cisco APIC releases.

The tables summarize significant changes to the organization and features in this guide through the current release. They do not list every guide change or every new feature in the release.

Table 1. New features and changed behavior for Cisco APIC release 6.2(3)

Feature or change

Description

Where documented

Support for Duo as an identity provider (IdP) for SAML

This feature adds official support for Duo Security as an identity provider (IdP) for remote SAML 2.0 authentication. Previously, the APIC GUI supported only Okta, ADFS, and Ping Identity.

For more information, see Create a provider, SAML authentication, and OAuth 2 / OIDC authentication.

CoPP support for HSRP

This feature adds HSRP support to the ACI per-interface CoPP framework. You can define HSRP policer rates and bursts through the APIC GUI to control traffic in hardware and drop packets that exceed the configured rates.

For more information, see Guidelines and Limitations for CoPP.

Table 2. New features and changed behavior for Cisco APIC release 6.2(2)

Feature or change

Description

Where documented

EPG-to-ESG Migration Assistant tool

This script-based tool automates the bulk migration of security contracts from EPGs to ESGs. The tool is bundled with the APIC software and is available at /data/esg migration.

For more information, see ESG Migration Assistant Tool.

Configure SSH host key sizes

Provides the ability to configure host keys for the SSHD server on the APIC and switches.

For more information, see Cisco APIC Security Configuration Guide, Release 6.2(x).

Allow TACACS+ authentication in FIPS mode

The ACI authentication framework now supports TACACS+ for remote user authentication in environments where FIPS compliance is required.

For more information, see Cisco APIC Security Configuration Guide, Release 6.2(x).

Table 3. New features and changed behavior for Cisco APIC release 6.2(1)

Feature or change

Description

Where documented

N/A

This document has no changes from the previous release.

N/A