BRKACI-2644 p3
BRKACI-2644 p3
BRKACI-2644 p3
Quick Review!
How does policy enforcement work L1 L2
• Each EPG is represented by a policy
tag, or PCTag
• Source Tag (sClass, or source class) EP2
EP1
is applied on ingress
• Source PCTag is carried in VXLAN EPG EPG
header Client Web
leaf1# show vlan id 64 extended PCTag PCTag
VLAN Name Encap Ports 16002 16003
---- -------------------------------- ---------------- ------------------
64 ciscoLive:PBR:Web vlan-3067 Eth1/1, Eth1/2,
leaf1# vsh_lc -c "show system internal eltmc info vlan 64" | egrep sclass
sclass: 16002
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
What are shadow EPGs? External and internal
interfaces
A ‘two armed’ example L1 L2
Cons Prov
Consumer Connector
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
EPGs and PCTags L1 L2
leaf1# vsh_lc -c "show system internal eltmc info vlan 64" | egrep sclass
sclass: 16002
leaf1# vsh_lc -c "show system internal eltmc info vlan 140" | egrep sclass
sclass: 16004
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 28
Shadow EPGs & contracts
L1 L2
• EPG Client to EPG Web (Redirect)
• EPG Web to EPG Client (Redirect)
• Consumer Conn to Client (uni-dir Filter) EP1 EP2
• Provider Conn to Web (uni-dir default)
EPG EPG
Client Web 16003
16004
16001 16002 Shadow
EPG
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 29
Common issues
1) Unable to ping Consumer connector L1 L2
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 30
Common Issues
2) Routing on Service Device L1 L2
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 31
Common Issues
2) Routing on Service Device L1 L2
BRKACI-2644 © 2020 Cisco and/or its affiliates. All rights reserved. Cisco Public 32