I have an EPG Web and an EPG DB, I have provided a contract in EPG web and consumed contract in EPG DB. The results are:
DB server can ping to Web server, and Web server can ping to DB server. How is this possible?
See the below screenshots. EPG Web provided the icmp contract, and EPG DB consumed the icmp contract.


The above is achieved due to these condition:
- The EPGs are under one VRF. No route leaking is required.
- The contracts have these defaults: Apply Both Directions and Reverse Filter Ports.