
Meet your instructor and outline the ccnp data center cac concentration exam, course flow, and nine sections while noting the challenging ac lab built with real hardware.
Explore advanced HCI and SDA concepts through Cisco ACI components (APIC, leaf and spine), real hardware, and VMware-based labs, for network engineers, SDN specialists, and cloud data center professionals.
Dean Armada introduces his extensive experience as a Cisco and data center trainer, highlighting expertise in Docker, Kubernetes, Python containers, LTM, advanced WAF, APM, EFM, and multi-vendor certifications.
Explore Cisco ACI basics, SDN, VXLAN, APIC components, and fabric configuration, including switches, ports, access policies, VPCs, underlay and overlay, contracts, VM integration, and management.
Explore a real hardware Cisco ACI lab with APIC, leaves, and spines. Test HCI topologies with multiple hosts and apps like web and database; book our hands-on lab.
Presents the Cisco ACI lab topology for apic management, detailing a spine-leaf fabric and apic connections to leaves, plus a layer 3 switch linking to the vcenter network.
Explore data center basics, compare traditional networks with software defined networking, and learn spine and leaf architecture, Cisco HCI, core hardware, and APIC access on version 5.2.
Explore enterprise campus networking, from layer 2/3 switches and wireless LAN controllers to data center fabric, security, automation, and hybrid cloud connectivity with public clouds.
Understand why data center networks use dedicated switches with high port capacity and virtualization, while SDN controllers and whitebox data planes enable scalable, VXLAN-enabled networks.
Explore software-defined networking basics, including control plane and data plane separation, central management, programmability, and OpenFlow-based policy with northbound and southbound APIs.
Explore spine and leaf architecture as a scalable alternative to three-tier data center design, where leafs connect to spines and a border leaf links to the router and Internet.
Explore how Cisco ACI delivers centralized, application-centric networking through endpoint groups, contracts, and policies, contrasting it with open flow, NSX, and other SDN approaches.
Learn how Cisco ACI and SDN enable a scalable spine-and-leaf data center with centralized policy, automation, and APIC management in hyper-converged deployments using VXLAN, BGP, and LDP.
Explore the Cisco Nexus 9000 data center switches, compare nx-os mode and aci mode, and learn about automation, spine-leaf architecture, vpc, fex, and apic policy automation.
Log in to the APIC GUI, view the system dashboard, and inspect APIC controllers and their connections to leaves 107 and 108, plus topology and IP settings.
Explore VXLAN fundamentals and Cisco ACI components, from spine and leaf topology to fabric discovery and APIC access via CLI, then practice checking interface and routing status.
Explore how vxlan resolves vlan limitations in scalable data centers by extending layer two across layer three boundaries, with vxlan id, udp 4789, and a gre comparison.
Explore vxlan basics in a spine-leaf network, where vtep endpoints on switches extend layer 2 across layer 3, map vxlan IDs to vlans, and perform encapsulation.
Explore how VXLAN decouples logical networks from physical infrastructure to enable spine leaf data centers, using 24-bit VNIDs and mac in IP encapsulation for layer two extension across data centers.
Explore Cisco ACI components, including fabric with spines and leaves and endpoint devices, and how automated discovery, VXLAN encapsulation, APIC control, and IS-IS routing enable scalable networks.
Explore the ACI fabric topology, where spine and leaf switches form the backbone in a partial mesh, with APIC enforcing policy across the fabric.
Explore Cisco ACI fabric discovery: view topology across pods, identify leaves and spines, register new nodes automatically, and learn how APIC DHCP and VXLAN influence leaf deployment.
Access APIC controllers via SSH and explore the APIC CLI. Learn to view APIC controller and switch details, distinguish leaves and spines, and assess out-of-band management and health status.
Log in to leaf switches via APIC or out-of-band IP, run show commands to verify version, VLANs, and overlay one routes learned by IS-IS; APIC pushes configuration to the switches.
Navigate the system dashboard to review controllers, leaves, and spines, then inspect leaf 106 in fabric inventory to identify the zero management interface causing the 80 score.
Explore Cisco ACI access policies, configure switch profile interface group policy and entity profile for a VPC between leaf 105 and leaf 106, verifying active port channels via CLI.
Explore virtual port channel concepts and how VPC provides redundant interfaces and devices with hash-based load balancing, VPC peer links, and policy-driven ACI design.
Configure Cisco ACI access policies by creating attach entity profile, VLAN pool, and interface policy group, then map an interface and switch profile for a server on leaf 101 e17.
Explore configuring VPC access policies in Cisco ACI by setting up VPC domain policies across leaf switches, creating a VPC policy group, and enabling static port-channel with VPC.
Navigate VPC and access policies in Cisco ACI, comparing channel port channels with VPC, examining load-balanced traffic, fast VPC peer configuration in HCI, and fabric-based synchronization.
Demonstrates configuring access policies and vpc via a wizard in Cisco ACI APIC, linking leaf 105 and 106 through port channel 9 and interface 1/21.
Shows how to verify automatically created Cisco ACI objects—switch profiles, VPC policy groups, AEPs, VLAN pools, and leaf interface profiles using the wizard-driven configuration.
See how APIC connects to leaves to discover devices and centralize configuration, then build a tenant with VRF, bridge domains, application profiles, EPGs, and contracts.
Explore pervasive gateway by showing how two web servers on different leaves share a pervasive SVI, enabling direct communication within the same EPG and VXLAN forwarding.
Explore the Cisco ACI policy model with tenants, VRFs, bridge domains, and EPGs, and learn how contracts, filters, and application profiles govern inter-EPG communication and pervasive default gateway roles.
Learn how to create configuration constructs in Cisco ACI using the APIC, including tenants, VRF, bridge domains, and application profiles, and use drag-and-drop topology for faster setup.
Explore Cisco ACI packet forwarding, covering underlay and overlay networking, EPCs, contracts, bridge domains, and both layer 2 and layer 3 forwarding in a hands-on lab.
Explore how the underlay auto-configures interfaces via apic dhcp. Enable is-is to connect spines and leaves; coop and mp-bgp with evpn vxlan share networks with spines as route reflectors.
Explore ai vxlan in the hci fabric, a proprietary overlay using ebgp from the source group, enabling packet normalization and cross-encapsulation communication across spines and leafs.
Compare underlay and overlay networks; underlay is the physical core enabling frame and packet forwarding, while overlay provides software-defined transport over the underlay using VXLAN and EVPN, auto-deployed by APIC.
Explore endpoint groups (EPGs) in Cisco ACI, detailing two examples with distinct subnets, VLANs, and bridge domains. Learn how contracts and filters control inter-EPG traffic, using web and database examples.
Explore advanced endpoint group design in Cisco ACI, with multi-subnet and multi-VLAN configurations inside EPGs and bridge domains, without contracts, using a layer 3 device as the gateway.
Learn how to create reusable contracts between web and database EPGs, apply subject rules with reverse filters, and understand consumer versus provider contracts for TCP traffic.
Learn to use a single contract across multiple application profiles, apply taboo contracts, and enable inter-tenant contracts via contract interfaces with the apply in both directions option.
Learn how EPGs group subnets and VLANs and how contracts and filters control traffic, including external firewalls and micro segmentation options for isolation.
Understand ACI endpoint learning, where endpoints' MAC and IP are learned by the data plane and shared via VXLAN across spines and leaves, using bridge domains and layer-3 configurations.
Explore layer 2 forwarding in Cisco ACI, where leafs learn destination macs, forward via local or global station tables, and use spine queries with hardware proxy or flooding.
Explore layer 3 forwarding in ACI using local and global station tables to route destination IPs, bridge domain subnets, and spine-leaf interactions, including external route learning via OSPF and MP-BGP.
Explore layer 2 and layer 3 forwarding in ACI, including bridge domains, EPG mappings, layer 2 unknown unicast handling, ARP flooding, and external routes shaping spine behavior.
Create an application profile topology for inter EPG on a layer two network, linking client, database, and web VMs to bridge domain 33 with VLANs 2097–2099.
Create a web contract between client and web server with a web subject and filter (ICMP and HTTP port 80), enable flooding in the bridge domain, and test connectivity.
Create a database EPG linked to a web EPG, define a 3306 filter for MySQL in a DB contract, and enable pervasive default gateway with unicast routing for inter-EPG communication.
Access the APIC and switches to verify bridge domain 33, EPGs, contracts, and vlan-vxlan encapsulation in SVIs, then ping the pervasive gateway to confirm reachability.
Discover how Cisco API integrates with the virtual machine manager to give APIC visibility into the virtual network layer, with a quick hypervisor refresher and an overview of virtual networking.
Explore hypervisor basics and virtual networking, including type 1 and type 2 hypervisors, ESXi, and vSphere client, with switches, VLANs, 802.1Q trunking, and inter‑VLAN routing via a layer 3 device.
Compare VMware's distributed switch and Cisco Nexus 1000V, spanning ESXi hosts for layer two VM communication, while Nexus 1000V adds layer three routing and IOS-like commands.
This lecture shows APIC VM integration and virtual networking, detailing how APIC creates a VM domain and VDS in vCenter, configures VLAN pools, and migrates VMs.
Connect a VMware host to EPGs by associating EPCs to an application profile, then create VLAN port groups from the VLAN pool and permit 3306 with a contract.
Enable Cisco ACI virtual networking by configuring a VMM domain and VDS in vCenter, automating VM mapping, EPG assignment, and VLAN port groups for end-to-end visibility.
Demonstrates creating a VMware vCenter integration for APIC, configuring a distributed switch (VDS) with a VLAN pool, adding credentials, migrating uplinks, and verifying VM connectivity.
Connects VMware host to EPGs by updating the application profile, deleting static ports, and mapping VMware domain to bridge domains with multiple subnets and pervasive default gateways.
Demonstrates VMware vSphere integration with APIC, where VLANs auto-create port groups from tenant and app profile, migrate VMs to a centralized VDS, and verify web and database connectivity.
Explore layer two and layer three external connectivity, comparing lx to out and bare metal host options, and examine routing from leaf to layer three device and bridge domain subnet.
Configure layer two out to extend the web EPG to an external bridge domain, using VLAN 1010 and a contract to permit traffic to the outside network.
Configure external layer 2 with a bare metal server using static path binding, leveraging the web BD and VLAN 1010 in trunk mode for the web EPG.
Explore Cisco ACI external connectivity: external layer 3 for reachability via routing protocols and external layer 2 for vlan-tagged extensions beyond the fabric. Learn static path binding and L2 out.
Configure external layer-2 connectivity with L2 out in Cisco ACI, set up an external bridge domain and EPG, define an ICMP contract, and verify reachability via ping.
Master external layer 2 with a bare metal host in Cisco ACI: remove layer 2 out contract, attach a bare metal server, configure VLAN encapsulation, and verify connectivity.
Explore external layer 3 in a Cisco ACI spine-leaf topology, configuring layer 3 out, bridge domains, and layer 3 extension with OSPF and a provider-consumer contract for web traffic.
Configure external layer 3 connectivity by creating a layer 3 out, linking bridge domains and VRFs, and enabling MP-BGP route reflectors for shared learned routes.
Configure external layer 3 connectivity in Cisco ACI by creating a layer 3 out with OSPF, enabling SVI interfaces, and associating a bridge domain to validate reachability.
Access and manage the APIC and fabric switches via out-of-band and inbound methods, configure management and ACI via CLI, and learn backups, role-based access control, and upgrades.
Configure out-of-band management by linking APICs, leaves, and spines to a dedicated out-of-band switch, then use the management tenant’s out-of-band EPG and external management contracts for FTP and Syslog.
Compare in-band and out-of-band management using dedicated data ports and a management switch, then configure inbound management with app EPGs, L2 out, L3 out, and contracts.
Explore out-of-band and in-band management under management tenants, including EPCs, contracts, subnets, and static node management addresses for secure access to APIC and fabric switches.
Configure the APIC via GUI, REST API, or CLI to define policies and connectivity across the fabric, centralizing management of a leaf-and-spine architecture.
Explore hands-on cli configuration on the apic and leaf switches, verify routes with show ip route, manage tenants, application profiles, epg, and contracts, and compare cli with gui.
Master Cisco ACI backup and restore with export/import and snapshots, and configure local or remote backups, plus scheduled rollbacks to the last known good configuration.
Explore how ACI uses authentication, authorization, and accounting (AAA) with local and external methods, RBAC roles, and security domains to control tenant access and policy configuration.
Upgrade the Cisco ACI data center by using the firmware upgrade repository to upload images, perform compatibility checks, and schedule controller and switch upgrades in groups for minimal downtime.
Wrap up by recapping Cisco ACI, SDN, VXLAN, and HCI concepts, then demonstrate VM visibility, external connectivity, and CLI-driven management tasks.
Identify the certifications or technologies you want to learn, spanning Cisco data center topics like Nexus and DC exams, security tools, DevNet, cyber ops, and related cloud courses.
Explore the L4 to L7 service integration with Cisco APIC and external platforms like F5, Palo Alto, and Firepower, and discuss why configuration is limited in Cisco HCI.
Celebrate completing the course and invite feedback, five-star ratings, and sharing with peers, while exploring more courses on cloud data center and cybersecurity on Udemy.
Celebrate completing the course and invite you to ask questions. Pursue CCNP data center goals and career in cloud data center and cybersecurity; connect on LinkedIn to share exam success.
Welcome to Cisco ACI - Certified Network Professional (CCNP) Data Center DCACI.
with Lab Demonstration - Real Hardware! New APIC Version.
Implementing Cisco Application Centric Infrastructure (DCACI) exam is a concentration exam/specialization and part of Cisco Certified Network Professional (CCNP) Data Center. It requires 2 Exam to be a CCNP Data Center. 1st the Core exam DCCOR and concentration exam such a DCACI
The exam covers configuration and management of Cisco Nexus 9000 Series Switches in ACI mode, how to connect the Cisco ACI fabric to external networks, it introduce Virtual Machine Manager (VMM) integration. You will gain knowledge in implementing key capabilities such as fabric discovery, policies, connectivity, VMM integration, and many others
Cisco ACI is an SDN solution that defines its network infrastructure based upon network policies. To make this possible Cisco has created the ACI Fabric OS, which is run by all systems within the ACI network. This shared OS makes it possible for the various switches within the ACI network to translate policies into infrastructure designs.
This 12 hour course will help you understand the underlying technologies Cisco Application Centric Infrastructure (ACI) Solution.
It is highly recommended that you are CCNA or at least knowledgeable in basics of Networking.
Target Audience
Network Engineers
SDN Specialist
Network Automation Engineer
Cloud and Data Center Network Engineers
Network Architect
Solutions Architect
Expectations
We will not talk about network basics
ACI Network Concepts is very different than the traditional
Made the course as simple as possible (ACI is complicated)
Course Flow
Introduction
Software Defined Networking (SDN) vs Cisco ACI
VXLAN and Cisco ACI Components
Cisco ACI Access Policies and vPC
Cisco ACI Packet Forwarding
APIC and VMM Integration
External Network Connectivity
APIC CLI and Management
Completion