Cisco ACI Microsegmentation
Cisco ACI Microsegmentation
ACI MicroSegmentation
!Credentials
ACI
M i c r o S e g m e n t a t i o n
Intra-EPG Isolation
Virtual Machines Based Attributes.
PODO3-WEB-SRV-01 •Centos
10.0.145.18 Node1
POD03-WEB-SRV-01.ecatsrtpdmz.cisco.com
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 1 of 11
:
Terminal
1 Tenant aci_p03_tenant
2 Expand Application Pro3les
3 Expand aci_p03_ap
4 Expand Application EPG's
5 Click on aci_p03_epg_web
6 Click on Policy
7 Click on General
8 Click On Intra EPG Isolation : Enforced
9 Click OK on the warning message
10 Click Submit
11 Submit Changes
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 2 of 11
:
After you click submit, you will notice the Pings are not longer working.
Let's revert back the Intra EPG isolation setting to Unenforced. In order to do this we
need to do the following steps:
1 Click Unenforced
2 Click Submit
3 Click Submit Changes
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 3 of 11
:
The Pings are back and working
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 4 of 11
:
DEV
PROD
External
Internal
Then, customers may create rules to allow or dissallow traQc. For example DEV
machines are not allow to talk with PROD machines. ACI can help achieve by creating
the necessary rules to block the desired communication.
1 Tenant aci_p03_tenant
2 Expand Application Pro3les
3 Expand aci_p03_ap
4 Expand Application EPG's
5 Click on aci_p03_epg_web
6 Click on Domains (VM's and Baremetal) aci_p03_dc3_vds
7 Double Click on your VMware domain and a new popup will be presented
8 Click on: Allow MicroSegmentation
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 5 of 11
:
9 Click Ok
1 Tenant aci_p03_tenant
2 Expand Application Pro3les
3 Expand aci_p03_ap
4 Right Click on uSeg EPGs
5 Click on Create uSeg EPG
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 6 of 11
:
6 Name: aci_p03_useg_web
7 Bridge Domain: aci_p03_bd_web
8 Click Next
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 7 of 11
:
9 Click on the + symbol to associate the uSeg with the VMM domain
aci_p03_dc3_vds
10 Domain Pro3le: aci_p03_dc3_vds
11 Deployment Immediacy: Immediate
12 Click Update
13 Click Finish
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 8 of 11
:
Step 5 - Create uSeg Attributes.
We need to de3ne the rule for our USeg, in this particular case we are going to be
using name as the VM attribute. Where POD03-WEB-SRV-01 and POD03-WEB-SRV-
02 will not be able to communicate
1 Tenant aci_p03_tenant
2 Expand Application Pro3les
3 Expand aci_p03_ap
4 Click on uSeg EPGs
5 Expand aci_p03_useg_web
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 9 of 11
:
6 Click uSeg Attributes
7 Click the plus sign (+) button
8 Select a Type... : VM - VM Name
9 Select an operator: Contains
10 Next to Contains: 02
11 Click Submit
12 Click on Submit Changes
After you click submit, you will notice the Pings are not longer working.
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 10 of 11
:
As you can see in this chapter, ACI can provide different type of MicroSegmentation
for different use cases. It is always import to understand the use case in order to
con3gure ACI with the right set of properties.
https://aci-lab.ciscolive.com/lab/pod3/segmentation/mseg 11/29/24, 08 56
Page 11 of 11
: