ACI 6.1.4 introduces the ability classify external subnet via ESGs: [ESG Support for L3OUT](https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/security-configuration/cisco-apic-security-configuration-guide-61x/endpoint-security-groups-61x.html#concept_05181FB503714A18AD4E7A035C1C54FE) The support is also extended to the set rules. This is addressed by https://github.com/netascode/terraform-aci-nac-aci/pull/291