ACI Best Practice EBook
ACI Best Practice EBook
OPERATIONAL
BEST
PRACTICES
https://www.cisco.com/go/aci
fi
Table Of Contents
Click on any module sub-entry to view content
Module One:
ACI Access Policies
Further Reading on Access Policies
Module Two:
Forwarding and Data Plane Concepts
Further Reading on Forwarding and Data Plane
Module Three:
ACI External Connectivity
Further Reading on External Connectivity
Module Four:
Segmentation and Contracts
Further Reading on Segmentation and Contracts
Module Five:
ACI Software Upgrade Best Practices
Further Reading in ACI Upgrade Topics
Table Of Contents
Click on any module item to view content
Module Six:
ACI Fabric Hardening
Further Reading for Fabric Hardening
Module Seven:
Policy Based Redirect Best Practices Part One
Further Reading for PBR Topics
Module Eight:
Policy Based Redirect Best Practices Part Two
Further Reading for PBR Topics
Module Nine:
Network Migration: Legacy to ACI
Further Reading on ACI migration Topics
Module Ten:
ACI Multi-Site Best Practices
Further Reading on ACI Multi-Site Topics
ACI Access Policies
version Sept 2021
Start Video Replay (Runtime: 1h22m)
In this video we will review the ins and outs of what we call Access Policies.
These are the policies you must create whenever you are connecting any type of
endpoint (physical or virtual) to the fabric. We will clarify common misconceptions,
teach about mistakes to avoid, plus provide some general guidance about how to
e ciently con gure the necessary objects. We will also demonstrate (where
possible) these con gurations on a live ACI deployment.
Click on any agenda item below to begin replay at that segment of the video
Access Policies:
If you want to know more…
Click on the links below for more details on the topic
• ACI Design Guide (Complete white paper) • VMM and Enhanced LACP
• # Access Policies Section • Design Guidance for Spanning Tree
• Port Tracking Feature (Connecting Servers) • Policy Viewer Free App at DC App Center
• ACI Virtualization Guide
TOC
ACI Forwarding and
Data Plane
version Jan 2022
Start Video Replay (Runtime: 1h28m)
In this video we will review the operation and process of how ACI handles both
Forwarding and Data Planes. First, we will embark on a review of how ACI
processes uses various control plane mechanisms to know where and how to
send tra c. We then explain how endpoint learning is handled with some
guidance on ne-tuning. We will complete the session with a review and
explanation of various Bridge Domain level options. A rm understanding of
these concepts is critical to achieving reliable and predication fabric operations.
Click on any agenda item below to begin replay at that segment of the video
• Fast & Flexible: Best Practices for ACI Forwarding • CiscoLive BRKACI-2641 - ACI Troubleshooting
(Video) Endpoints
Click on any agenda item below to begin replay at that segment of the video
External Connectivity:
If you want to know more…
TOC
fi
fi
Segmentation and
Contracts
version April 2022
Start Video Replay (Runtime: 1h29m)
When it comes to Security, ACI is built as a fabric wide stateless rewall. This
means security is built-in at a foundational operational level. ACI also takes a cloud
based approach in which the default behavior is to deny communication unless it is
explicitly permitted. This is where the concepts of Contracts and Filters come
into being. This video will go in-depth to describe the operational concepts of ACI
segmentation, including advice on tuning and optimizing the hardware resources in
order to scale to the size of a whole fabric at line rate.
Click on any agenda item below to begin replay at that segment of the video
• ACI Best Practices: Stay Secure with • CiscoLive BRKACI-2301: Practical Applications
Segmentation and Contracts (Video) of Cisco ACI Micro Segmentation
TOC
ACI Software Upgrade
Best Practices
version Nov 2021
Start Video Replay (Runtime: 1h23m)
ACI is a sophisticated interworking of leafs and spines, all managed by the APIC
controller. Each of these nodes has a software component that requires updating
sooner or later. To get the latest features, bug xes and hardware support we
make version recommendations that often trigger an upgrade. In this video we will
explore the process of upgrading ACI, gaining an understanding of what happens
behind the scenes. We teach how to prep your fabric for a smooth upgrade, and
how to avoid those unintended mistakes that can result in longer or failed upgrades.
Click on any agenda item below to begin replay at that segment of the video
• ACI Best Practices: Smooth Sailing for your • Bug Note / Guidance on setting IS-IS Policy value
Upgrade (Video)
• ACI Pre-upgrade Validation Script (Github)
• ACI Upgrade / Downgrade Guide • TechNote with details on enabling encryption for
• ACI Upgrade Handy Checklist backups
• APIC HW/SW and Compatibility Release Notes • Nexus 9000 Switch Release Notes
TOC
ACI Fabric
Hardening
version Sept 2022
Start Video Replay (Runtime: 1h25m)
In earlier modules we learned about security and segmentation of endpoint tra c
that lives in the tenants of the fabric. It is equally important to also consider a viable
security posture for the infrastructure components that make up the fabric itself. In
this video we will start with the principles of secure operations. We will then break
out to discuss security hardening approaches for each of the Management, Control
and Data Planes respectively. As always, we will demonstrate where possible on a
live fabric to help you translate these concepts into your own environments.
Click on any agenda item below to begin replay at that segment of the video
Click on any agenda item below to begin replay at that segment of the video
• Use Cases and Deployment Modes • PBR Con guration and Demo
Click on any agenda item below to begin replay at that segment of the video
• White Paper: Service Graph Design • White Paper: Multi-Site Service Node Integration
• White Paper: Policy Based Redirect Design • CiscoLive BRKDCN-3610: ACI L4-L7 Policy-
Based Redirect (PBR) Deep Dive and Tips
• White Paper: ACI Contract Design
• White Paper: Multi-Pod Service Node Integration
TOC
Migrating from Legacy
to ACI
version May 2023
Start Video Replay (Runtime: 1h29m)
Nearly every customer coming to ACI starts with some sort of existing classic DC
infrastructure. It could be from Cisco, or from other vendors. In any case, such
customers ask early on about how a migration from existing network to ACI can be
done. In this video we talk about securely extending your legacy into ACI, give
some design guidance on ways to plan a migration, things to keep track of during
the migration of workloads with an eye on minimizing interruption. We will include
guidance on how to avoid common mistakes that show up in migration projects.
Click on any agenda item below to begin replay at that segment of the video
ACI Migration:
If you want to know more…
• White Paper: Migrating Existing Networks to • APIC Layer 2 Networking Con guration Guide,
Cisco ACI Release 6.0(x)
TOC
fi
Multi-Site Best
Practices
version Oct 2023
Start Video Replay (Runtime: 1h27m)
When it comes to expanding the data center fabrics beyond the boundaries of one
site, ACI Multi-Site has proven to be a very popular choice. Given the importance of
workloads that live, move or are stretched across sites, it becomes important to
build from a solid design and implementation plan. In this video we will discuss how
to best deploy Nexus Dashboard Orchestrator (including version recommendations),
before we move to guidance for creating NDO schemas and templates which are the
policy building blocks for ACI Multi-Site operations. We will also include guidance
on site to site connectivity, L3outs, and L4-L7 service insertion.
Click on any agenda item below to begin replay at that segment of the video
https://www.cisco.com/go/aci