A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?
Trap 1: The VXLAN tunnel interface on the spine
Spine switches in an ACI fabric forward VXLAN-encapsulated traffic based on the fabric's forwarding tables but do not host EPG-level contract enforcement. Contract policy is enforced at the leaf where endpoints attach, so the spine tunnel interface is not the enforcement point described.
Trap 2: The bridge domain subnet SVI on the border leaf
A bridge domain SVI provides default gateway functionality for a subnet, not contract enforcement between EPGs. Contracts are applied at the leaf access policy layer using the EPG and contract relationship, so the SVI is not where the permitted TCP port 443 rule is enforced.
Trap 3: The APIC controller cluster policy compiler
The APIC cluster compiles and distributes policy to the leaves but does not sit in the data path, so it cannot enforce the TCP 443 permit rule on live traffic. Enforcement occurs on the leaf switch hardware, making APIC the policy source rather than the enforcement point.
- A
The VXLAN tunnel interface on the spine
Why it fails: Spine switches in an ACI fabric forward VXLAN-encapsulated traffic based on the fabric's forwarding tables but do not host EPG-level contract enforcement. Contract policy is enforced at the leaf where endpoints attach, so the spine tunnel interface is not the enforcement point described.
- B
The bridge domain subnet SVI on the border leaf
Why it fails: A bridge domain SVI provides default gateway functionality for a subnet, not contract enforcement between EPGs. Contracts are applied at the leaf access policy layer using the EPG and contract relationship, so the SVI is not where the permitted TCP port 443 rule is enforced.
- C
The policy enforcement point on the leaf where the EPGs reside
In ACI, the leaf switch acts as the policy enforcement point, translating contracts into hardware ACL and forwarding rules applied to the EPG interfaces. When a contract permitting TCP 443 is attached between EPGs, the leaf enforces that filter for traffic between them, which is exactly the construct required.
- D
The APIC controller cluster policy compiler
Why it fails: The APIC cluster compiles and distributes policy to the leaves but does not sit in the data path, so it cannot enforce the TCP 443 permit rule on live traffic. Enforcement occurs on the leaf switch hardware, making APIC the policy source rather than the enforcement point.