September 2022

ACI Contract

The ACI security architecture plays a foundational role toward Zero Trust architecture and Micro Segmentation initiatives in data center. In this blog post ACI contract structure, contract inheritance, contract labels are discussed. EPG|ESG classification, policy enforcement, and ways of deploying contracts from Macro to micro level are also covered.

ACI Contract Read More »

Two Arm Load Balancer with ACI PBR destination in an L3out

When inserting a load balancer into a Cisco ACI fabric, it is important to understand the desired traffic flow, the advantage of using the ACI fabric anycast gateway, the benefit of selective traffic redirection and if DSR is required. Load balancers can be inserted into ACI fabric using the following deployment options. Policy based redirect is a feature to selectively steer traffic to service nodes. PBR with load balancers (one-arm, two-arm) plays a key role on returning traffic back to the same load balancer as the incoming traffic while keeping the client IP as a source IP.

Two Arm Load Balancer with ACI PBR destination in an L3out Read More »

ACI Custom EPG Name for Simple and Meaningful Port Group Naming

An EPG with VMM domain association creates a port group on the APIC managed DVS. The name for the port group defaults to ‘Tenant_name|AP_name|EPG_name’. The name, depending on how the tenant, application profile and EPG are named, may not be simple or meaningful for the VMWare admin. The solution is custom EPG name. An EPG can optionally have a custom name with the VMM domain association. Beginning in release 4.2(3), custom EPG name is used to create a port group with a simple and meaningful name when the default ‘Tenant_name|AP_name|EPG_name’ naming doesn’t meet the need of the VMWare admin’s standard.

ACI Custom EPG Name for Simple and Meaningful Port Group Naming Read More »