Explains the Cisco ACI contract-based security model and provides guidance for configuring traffic filters, policy enforcement, taboos, and ACL permit and deny logging.
This chapter contains the following sections:
Contracts in the ACI fabric security policy model
Contracts define the traffic that can pass between endpoint groups (EPGs) in the Cisco Application Centric Infrastructure (ACI) fabric.
Security policy enforcement
Leaf switches enforce security policies by identifying the source and destination endpoint groups (EPGs) of traffic that enters the fabric.
Multicast EPG security
Multicast security policies control which endpoint groups (EPGs) can send traffic to or receive traffic from a multicast group.
Taboo contracts
Taboo contracts deny specific traffic that another contract would otherwise permit between endpoint groups (EPGs).
ACL contract permit and deny logs
Access control list (ACL) contract logs record traffic that contract rules permit or deny in the Cisco Application Centric Infrastructure (ACI) fabric.
Enable ACL contract permit or deny logging by using the GUI
Enables access control list (ACL) logging for flows and packets that a contract subject permits or denies.
Enable ACL contract permit logging by using the NX-OS-style CLI
Enables access control list (ACL) logging for packets and flows that contract permit rules allow.
Enable ACL contract permit and deny logging by using the REST API
Enables access control list (ACL) logging for contract subjects that contain permit or deny actions.
Enable taboo contract deny logging by using the GUI
Enables access control list (ACL) logging for packets and flows that a taboo contract denies.
Enable taboo contract deny logging by using the NX-OS-style CLI
Enables access control list (ACL) logging for packets and flows that taboo contract rules deny.
Enable taboo contract deny logging by using the REST API
Enables access control list (ACL) logging for traffic that a taboo contract denies.
View ACL permit and deny logs by using the GUI
Displays access control list (ACL) logs for permitted and denied network traffic.
View ACL permit and deny logs by using the NX-OS-style CLI
Displays access control list (ACL) permit and deny logs for Layer 2 and Layer 3 packets and flows.
View ACL permit and deny logs by using the REST API
Retrieves access control list (ACL) permit and deny log entries by querying the applicable managed object class.
Configure SSH host key sizes by using the GUI
Configures one or more Secure Shell (SSH) host key algorithms and key sizes for console access.