Professional Documents
Culture Documents
Introduction To ACI - BRKDCN-1001
Introduction To ACI - BRKDCN-1001
Intro to ACI
#CiscoLive
Cisco Webex App
Questions?
Use Cisco Webex App to chat
with the speaker after the session
How
1 Find this session in the Cisco Live Mobile App
2 Click “Join the Discussion”
3 Install the Webex App or go directly to the Webex space Enter your personal notes here
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 3
• Fabric Basics
• Policy Model
Agenda • Architectural Deployments
• Day 2 and beyond
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 4
Fabric Basics
ACI: One Network, any location
ACI
Cloud
Containers
* *
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 6
ACI Anywhere
IP WAN IP WAN
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 7
The DC network before The DC network NOW
Classic modular switching ACI
Supervisors (1 or 2)
APICs
(1, 3 or more)
Fabric Modules (3-6)
Up to 18 RUs Scale-up
SPINE
(1 to 6)
Linecards (Copper, Fiber, 1/10G)
Zero-touch VXLAN
No STP
LEAVES
(1 to 200 or more*) Scale as you need
BEFORE
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 11
ACI: How difficult was it to bring up?
What tasks & configuration did ACI just saved me from doing manually on every switch
BEFORE
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 12
ACI: How difficult was it to bring up?
What tasks & configuration did ACI just saved me from doing manually on every switch
BEFORE NOW
External to Internal Route redistribution
& Control Plane (MP-BGP, QoS, etc)
VLAN 10
VLAN 20BD
BD VLAN 30 BD
10.10.10.1/24
10.10.20.1/24 10.10.30.1/24
VLAN 10
VLAN 20EPG
EPG VLAN 30 EPG
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 16
The ACI Policy Model – Migrating into ACI
Tenant
Global VRF/Routing Table and Protocol Connect
To External
Switch
VLAN 10 BD VLAN 20 BD VLAN 30 BD
10.10.10.1/24 10.10.20.1/24 10.10.30.1/24
L2 External
(802.1q Trunk)
VLAN 10 EPG VLAN 20 EPG VLAN 30 EPG
L3 External
(Routed Interface)
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 17
The ACI Policy Model – Extending the configuration
Tenant
Global VRF/Routing Table and Protocol Connect
To External
Switch
VLAN 10 BD
10.10.10.1/24
L2 External
AD_SVR Prod_SQL Print Svc (802.1q Trunk)
XenApp
VLAN 10 EPG
VM VM VM
VM VM VM L3 External
(Routed Interface)
VM VM
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 18
Advancing the ACI Configuration
AppApp
1 -1 - App 1 -
App Tier Web Tier External
Database EPG
To DB
Tier EPG
Only SQL
Only tcp/2048 Only HTTPS
IP WAN IP WAN
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 21
ACI MultiPod
The evolution of a stretched fabric
Inter-Pod IP Network
Site A Site B
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 22
ACI: Physical Remote Leaf
Extend ACI to Satellite Data Centers
Port Speed:
1/10/40/100G
Site A Remote
Location
VM VM VM VM VM VM VM VM VM VM VM VM VM VM
Zero Touch Auto Two switches per site Stretch EPG, BD, VRF, DC Migration /
Discovery of Remote Leaf Up To 128 Remote Leaf Tenant, Contract OTV replacement
Switches
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 23
ACI Multi-Site Nexus Dashboard
Orchestrator Consistent Policy across sites
Single Point of Orchestration
Fault Isolation
Scale
Site A
Site D
Site B
VM VM VM
VM VM VM
VM VM VM
Scale
Site A
Site C
Site D
Site B
VM VM VM
VM VM VM
VM VM VM
IP SG
Web
SG Rule
SG
APP
SG Rule
SG
DB
EPG
Contract
EPG
Contract
EPG Network
Web APP DB
AWS Region
IP
Network ASG ASG ASG
NSG NSG
Web APP DB
VM VM VM
Azure Region
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 26
The network-admin challenge
Provisioning and monitoring complexity = Risk
NX-OS ACI
Subscription/
Separate Infrastructure + Tenant Account Account/Project
Resource Group
VXLAN
Bridge Domain/
VLAN CIDR/Subnet Subnet Subnet
Subnet
Access-list (ACL) Contracts & Filters Security Group Rules Security Rules Firewall Rules
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 27
ACI
Day 2 and Beyond
Cisco Nexus Dashboard Powering automation
Simple to automate, simple to consume Unified agile platform
Orchestrator Custom/third-
party
Cisco Nexus
Dashboard Orchestrator
Orchestrator Custom/third-
party
Cisco Nexus
Dashboard Insights
Orchestrator Custom/third-
party
Cisco Nexus
Dashboard Data Broker
Orchestrator Custom/third-
party
Error detection,
Mitigate
latency, packet drops
Prevent outages
Control plane issue
Hardening checks
Automated alerts
Cisco Nexus Availability Software hardware
Explorer
Dashboard recommendations
Insights
Pre-change analysis PSIRT notices
Compliance alerts EoS/EoL notices
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 36
How it works
Data
enrichment
Complex
correlation Cisco Nexus
Dashboard Insights
Artificial
intelligence and
machine learning
Software and
hardware telemetry
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 37
Key Takeaways
• Consistent SDN enabled network policy
across all the switches within a fabric
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 38
Technical Session Surveys
• Attendees who fill out a minimum of four
session surveys and the overall event
survey will get Cisco Live branded socks!
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 39
Pay for Learning with
Cisco Learning Credits
Cisco Learning and Certifications (CLCs) are prepaid training
vouchers redeemed directly
From technology training and team development to Cisco certifications and learning with Cisco.
plans, let us help you empower your business and career. www.cisco.com/go/certs
Here at the event? Visit us at The Learning and Certifications lounge at the World of Solutions
#CiscoLive BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 40
• Visit the Cisco Showcase
for related demos
BRKDCN-1001 © 2022 Cisco and/or its affiliates. All rights reserved. Cisco Public 41
Thank you
#CiscoLive
#CiscoLive