
Explore Cisco's application centric infrastructure, a policy based framework powered by the APIC controller, using endpoint groups and contracts to govern networking and security.
Explain the spine-leaf two-tier architecture of the ACI fabric, using underlay IS-IS with IP unnumbered adjacencies and VXLAN overlays for scalable VTEP addressing.
Bootstrap the APIC to initialize a Cisco ACI fabric by provisioning the tap pool, infra vlan four, and bridge domain multicast range via the SMC.
Explore the Cisco ACI fabric discovery process, including LLDP-based auto discovery, IP addressing for leaves and spine, and VXLAN tunnel endpoints enabling the fabric's auto assembly.
Explore how tenants, contexts (vrfs), and bridge domains organize management, policies, and vxlan overlays in apic, enabling subnet reuse and fabric-wide bridging and routing.
Create and manage tenants in Cisco ACI as logical containers for security domains, policies, and resources, and configure VRFs and bridge domains within each tenant.
Create a bridge domain in the Ami tenant as a container for three subnets, illustrating how ACI uses VXLAN, SVI, and VRF isolation.
Learn to configure and compare out-of-band and in-band management for Cisco ACI, using APIC, Nexus switches, and an out-of-band network to connect to vCenter and other VM managers via SSH.
Configure out-of-band management in aci by creating a node management address pool in the management tenant, assign three out-of-band ip addresses, and verify ssh access to leaf and spine switches.
Explore how the ACI fabric forwards unicast traffic using vxlan encapsulation, anycast vteps, and the pervasive svi gateway for efficient local and global routing across leaf and spine switches.
Explore how ACI interface policies shape interface policy groups (ipgs) and enable configurable link level settings, speed, protocol controls like cdP, lldp, lacp, ms cabling, in-band and out-of-band management.
Explore configuring reusable interface policies in Cisco ACI, including link level speed and duplex, CDP and LLDP options, and port channel methods such as static, lacp, and mac pinning.
Identify leaf switches and build switch profiles to define the physical fabric, then create interface profiles and selectors for each port to implement policy-driven access.
Create switch profiles for each leaf and a VPC domain, then link them with domains and attachable entity profiles, enabling interface selectors and interface profiles to be configured later.
Configure interface profiles and precise interface selectors to map leaf switch ports to the fabric, maintaining consistency across leaf switches and linking to switch profiles for VLANs and endpoints.
Configure interface policy groups to bundle port policies into reusable port profiles, apply them to single or multiple leaf switch ports, and manage port channels.
Create and reuse interface policy groups to bundle CDP, LLDP, and LDP policies for access ports and port-channel interfaces, ensuring a unique group per port channel or VPC in ACI.
Explore how vlan pools in aci classify traffic using vlan, vxlan, and vni, and how static and dynamic vlan allocations map to bridge domains and endpoint groups.
Configure VLAN pools in ACI by establishing static pools for bare metal hosts and dynamic pools for VM domains, then map VLANs to VXLAN VNIs and link to EPGs.
Learn how domains connect devices to the fabric, including physical, vm, and external layer two and three domains, and how VLAN pools and EPGs tie to tenants.
Explore the attachable access entity profile (AEP), a global policy that binds domains, VLAN ranges, and interface policy groups to leaf switches via the APIC, enabling selected VLAN provisioning.
Configure physical and external domains in the ACI fabric, map vlan pools to bare metal host domains with AAEPs, and link ARP and interface policy groups to enable vlan provisioning.
Explore endpoints, endpoint groups, and application profiles to define policy. Understand contracts, filters, and subjects to govern inter-epg communication.
Create and manage contracts, subjects, and filters in Cisco ACI to control inter-EPG communication, specify service ports, reuse filters, and apply taboo contracts for denies.
Learn how to connect bare-metal hosts to the ACI fabric using physical configurations, VLAN pools, and a static path binding to map tagged or untagged traffic to an EPG.
The demo configures two bare-metal hosts in a single ACI EPG within the same subnet, mapping VLANs to a bridge domain and enabling free intra-epg traffic via VXLAN.
Demonstrates the flexibility of the aci fabric by configuring bare-metal hosts in a single epg across subnets, establishing default routes, and achieving end-to-end ip reachability within a bridge domain.
Demonstrates separating bare-metal hosts into two EPGs in an ACI fabric, creating an any contract as provider-consumer, configuring static path bindings, and validating cross-EPG connectivity.
Explore how the ACI fabric integrates with vCenter to build a distributed virtual switch, map VM domains to EPGs, and manage VLAN, VXLAN, or NVGRE tagging.
Integrate the APIC with vCenter to build a VMware distributed virtual switch, map vcenter port groups to epgs, and implement a three tiered app with contracts.
Refine EPG contracts by deleting old ones and creating DB app and Web-to-app contracts with SSH, ICMP, and HTTP filters. Demonstrate provide/consume relationships and APIC-driven VM integration with EPGs.
Explains external layer-3 connectivity in Cisco ACI, detailing border leaf routing, multiprotocol BGP with route reflectors, OSPF/iBGP, static routing, and public versus private subnets within EPGs for transit routing.
Configure an external routed domain with eigrp in the aci fabric, add vlan 351 to the pool, define the eigrp node and interface policy, and verify routes and reachability.
Explore how ACI enables VPC integration with leaf switches and a VPC domain. Use an explicit protection group and the fabric to manage interface profiles and policy groups.
Configure vpc within aci by establishing a vpc domain between leaf switches and creating a vpc interface policy group to assign ports to the vpc. Verify peers and port channels.
Connect your hci fabric to external layer two domains using external bridge domains and EPG configurations. Learn about VLAN tagging, VLAN pools, contracts, and spanning tree considerations for cross-domain communication.
Extend a bridge domain outside ACI by configuring an external layer two domain and external bridged network using vlan 351 linked to a web app contract.
Demonstrates configuring LDAP authentication for Cisco ACI with Active Directory by adding a custom AV pair attribute, creating an LDAP provider and domain, and mapping users to an admin role.
Get to know Cisco ACI with your instructor, Jason Lunde, a certified CCIE in both Data Center and Routing and Switching. In this initial series we will not overwhelm you with information, but rather strive get you accustomed to ACI, how it operates, and how to actually do the work within the APIC GUI! This is about 9 hours worth of ACI goodness! If you are preparing for the DC v2 exam, this will be the perfect series to obtain the information that you will need to know in order to be successful in the lab examination (within the scope of ACI).
You will learn more about:
• SDN (Software-defined Networking)
• VXLAN
• ACI Components
o Spine and Leaf Switches
o APIC Controllers
Unlike most traditional courses, I will take you through the implementation of an ACI infrastructure from a real-world perspective. You will learn most of the terminology associated with Cisco’s ACI, as well as the basic networking constructs such as bridge domains and contexts.
Most implementation are not going to be ‘strictly ACI’ either, so I take you though how to extend layer-2 and layer-3 out of, and through the ACI domain. This includes using some of our favorite protocols such as BGP, OSPF, EIGRP, and vPC!
Note: My course is developed using ACI 1.2(x) release.