: Whats New in the Panorama Plugin for Cisco ACI 2.0.0
Focus
Focus

Whats New in the Panorama Plugin for Cisco ACI 2.0.0

Table of Contents

Whats New in the Panorama Plugin for Cisco ACI 2.0.0

The Panorama plugin for Cisco ACI 2.0.0 introduces the following features.

New Monitored Attributes

Panorama plugin for Cisco ACI 2.0.0 introduces two new monitored attributes that allow you enforce security policy based Layer 2 external outside network endpoint groups and subnets under bridge domains. These new monitoring attributes will appear as match criteria when configuring dynamic address groups.
  • cisco.cl_<cluster>.tn_<tenant>.l2out_<L2-external-endpoint>—this tag groups IP addresses into dynamic address groups based on L2 external endpoint and displays the name of you cluster, tenant, and L2 external endpoint.
  • cisco.cl_<cluster>.tn_<tenant>.bd_<bridge-domain>.subnet_<subnet>—this tag groups IP address into a dynamic address group based on subnet and displays the name of you cluster, tenant, bridge domain, and subnet.

Panorama Plugin for Cisco ACI Dashboard

The Panorama plugin for Cisco ACI 2.0.0 introduces a new dashboard that gives you visibility the monitored attributes, the dynamic address groups the attributes are associated with, and where the dynamic address groups are used in security policy.
Each tile is clickable and allows you to drill-down and view additional details about the ACI object being monitored by the plugin. The example below shows the dashboard after clicking the Service Graphs tile. It displays a list of the service graphs monitored by the plugin, the producer EPG associated with each service graphs, and the Palo Alto Networks firewall in line with the service graph.