Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

Enable taboo contract deny logging by using the GUI

Want to summarize with AI?

Log in

Enables access control list (ACL) logging for packets and flows that a taboo contract denies.


Apply the log directive to a taboo contract filter to record matching denied traffic.

Procedure

  1. On the menu bar, choose Tenants > tenant_name .

  2. In the Navigation pane, expand Contracts .

  3. Right-click Taboos and choose Create Taboo Contract .

  4. In the Create Taboo Contract dialog box, configure the taboo contract.

    1. In the Name field, enter a name for the taboo contract.
    2. Optional: In the Description field, enter a description.
    3. Next to Subjects , click + .
  5. In the Create Taboo Contract Subject dialog box, configure the subject and select a filter.

    1. In the Specify Identity of Subject area, enter a name for the subject.
    2. Optional: Enter a description of the subject.
    3. Next to Filters , click + .
    4. From the Name drop-down list, choose an existing filter, choose a default filter, or choose Create Filter .

      The default filters include tenant_name /arp , tenant_name /default , tenant_name /est , and tenant_name /icmp .

  6. If you chose Create Filter , configure the filter.

    1. In the Specify Filter Identity area, enter a name and, optionally, a description.
    2. Expand Entries , enter a name for the entry, and configure the criteria that identify the traffic to deny.
    3. Click Update .
    4. Click OK to create the filter and return to the Create Taboo Contract Subject dialog box.
  7. For the selected filter, choose log from the Directives drop-down list, and click Update .

  8. In the Create Taboo Contract Subject dialog box, click OK .

  9. In the Create Taboo Contract dialog box, click Submit .

    Deny logging is enabled for traffic that matches the taboo contract filter.