With ACI native contract, by default the filter would be applied bi-directionally. For example, if a contract blocks RDP is applied between consumer EPG1 and provider EPG2. ACI fabric would prevent workload in EPG1 to RDP to workload in EPG2. ACI fabric would also prevent workload in EPG2 to RDP to workload in EPG1.
With service graph PBR, i have a contract to redirect RDP traffic to firewall. When i apply the service graph between consumer EPG1 and provider EPG2. RDP traffic from EPG1 to EPG2 is redirected to firewall but RDP traffic from EPG2 to EPG1 is not redirected…The PBR contract does have bidirectional enabled…
Anyway to apply service graph PBR bidirectionally, like how the native contract is applied?