New and Changed Information

This chapter contains the following sections:

New and Changed Information

The following table provides an overview of the significant changes to the organization and features in this guide up to this current release. The table does not provide an exhaustive list of all changes made to the guide or of the new features up to this release.

Table 1. New Features and Changed Behavior for Cisco APIC Release 5.0(x)

Feature or Change

Description

Where Documented

Endpoint Security Groups

Endpoint Security Groups (ESGs) are the new network security component in Cisco ACI infrastructure.

Endpoint Security Groups

DUO two factor authentication

The two factor authentication with DUO proxy in Cisco APIC.

DUO Two Factor Authentication

Per-Leaf RBAC

The ability to assign a physical leaf to a security domain for configuration and management.

Assigning a Node to a Domain

Consolidated Privileges

The number of privileges is reduced from earlier releases, as many related legacy privileges are consolidated.

Note

 
When upgrading from an earlier release to Cisco APIC Release 5.0(x), you must reconfigure any rules, policies, or roles that use the more granular earlier privileges.

Remapping of Legacy Privileges

Restricting Infra VLAN Traffic

To strengthen isolation between hypervisors in the fabric, you can restrict Infra VLAN traffic to only network paths specified by Infra security entry policies.

Restricting Infra VLAN Traffic