Taboo contracts deny specific traffic that another contract would otherwise permit between endpoint groups (EPGs).
A taboo contract is a unidirectional policy construct that denies traffic matching specified criteria as the traffic travels toward the EPG that provides the taboo contract.
-
A taboo contract can deny traffic from any EPG or a specific EPG.
-
A filter defines the traffic that the taboo contract denies.
-
The taboo rule takes precedence over a standard contract that permits the matching traffic.
ACI policy enforcement
By default, different EPGs cannot communicate unless a contract or another policy construct permits the traffic. Contracts are managed objects in the Cisco Application Centric Infrastructure (ACI) policy model.
Administrators configure policy through the management model. The fabric renders the policy into the applicable hardware configuration.
Alternative deny mechanisms
Beginning with Cisco Application Policy Infrastructure Controller (APIC) Release 3.2(x), Cisco Nexus switches whose model names end in -EX or -FX support additional methods for denying traffic in a standard contract:
-
Configure a subject with the Deny action.
-
Configure a contract exception or subject exception to block traffic that matches a specified pattern.