Cloud ACI 5.2: AWS Enhancements in TGW with TGW Connect Attachments

Cloud ACI 5.2 for AWS can now use TGW Connect Attachment to enhance the previous ACI/AWS integration.  You can read more about what we had pre cAPIC 5.2 by using only TGW VPC attachment at a previous writeup. Before we start discussing and showing how TGW Connect Attachment benefits this integration, let’s quickly discuss what … More Cloud ACI 5.2: AWS Enhancements in TGW with TGW Connect Attachments

Cloud ACI 5.2: ACI/Azure Tenant vNET Peering across Azure Acitive Directories

From Cloud APIC 5.2 you can configure Tenant vNET peerings across Azure Active Directories. This will be very useful for B2B connectivity. Prior to this tenant vNET peerings for Azure using cAPIC was only possible across subscriptions in the same Azure Active Directory. To Follow along this Proof Of Concept Lab in your own Azure … More Cloud ACI 5.2: ACI/Azure Tenant vNET Peering across Azure Acitive Directories

Cloud ACI 5.2: Azure Brownfield Integration with ACI Fabric

If you already have resources deployed in Azure, you can now connect your brownfield vNETS to the Azure cAPIC vNETs using vNET Peering.  This means your connectivity from ACI Fabric vNETS to the brownfield vNETS can go over Azure’s backbone directly.  Security Policies can be attached for this connectivity based on requirements. You can follow … More Cloud ACI 5.2: Azure Brownfield Integration with ACI Fabric

Cloud ACI 5.2: Interconnecting ACI Fabrics Over Cloud Provider’s Backbone at High Speed for both AWS and Azure

If you have 2 or more Cloud Fabrics in the same Cloud Provider you can now (from cAPIC 5.2) use the Cloud Providers backbone for interconnecting these Data Centers (DCI). Prior to this you needed to build IPSec tunnels over the Internet between the sites to achieve this. This gives you the benefit of high … More Cloud ACI 5.2: Interconnecting ACI Fabrics Over Cloud Provider’s Backbone at High Speed for both AWS and Azure

ACI with IPv6

This is a running list of ACI/IPV6 support notes that I will add to as I learn more items.  Most of the items here have been taken from Cisco ACI Infrastructure Fundamentals Release 5.1(x), Networking and Managemcnt Connectivity.  In addition I’ve also added items here that I’ve obtained by querying the field. Supported: IPv4 only, … More ACI with IPv6

Using ESGs (Endpoint Security Group) in ACI fabric to migrate from Network Centric to Application Centric

In Release 5.0 of ACI a new feature, ESGs was released.  This feature effectively allows us to decouple the security policy construct FROM EPGs which have a relationship to BDs  TO  ESGs which have a relationship to VRFs. I had planned to read up on this feature and rewrite the previous article that I had … More Using ESGs (Endpoint Security Group) in ACI fabric to migrate from Network Centric to Application Centric

Understanding ACI TCAM Utilization & Optimization

Being organized and creating consistent configurations is a great virtue in the Networking / SDN / Cloud and computing field.  ACI is no exception to that rule.  Haphazard, Inconsistent and thoughtless configurations will increase your work and complexity/understanding of your infrastructure once your  Fabric grows.  In addition it will make it more prone to failures … More Understanding ACI TCAM Utilization & Optimization

ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with North South Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)

In a previous article for Multinode Service Graphs with Horizontal Scaling of Firewalls for East/West traffic on Azure I had described and guided you step by step on how to configure and test that scenario. I have had quite a few folks reach out to me and request that I do a similar writeup for … More ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with North South Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)