Using ESGs (Endpoint Security Group) in ACI fabric to migrate from Network Centric to Application Centric

In Release 5.0 of ACI a new feature, ESGs was released.  This feature effectively allows us to decouple the security policy construct FROM EPGs which have a relationship to BDs  TO  ESGs which have a relationship to VRFs. I had planned to read up on this feature and rewrite the previous article that I had … More Using ESGs (Endpoint Security Group) in ACI fabric to migrate from Network Centric to Application Centric

Understanding ACI TCAM Utilization & Optimization

Being organized and creating consistent configurations is a great virtue in the Networking / SDN / Cloud and computing field.  ACI is no exception to that rule.  Haphazard, Inconsistent and thoughtless configurations will increase your work and complexity/understanding of your infrastructure once your  Fabric grows.  In addition it will make it more prone to failures … More Understanding ACI TCAM Utilization & Optimization

ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with North South Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)

In a previous article for Multinode Service Graphs with Horizontal Scaling of Firewalls for East/West traffic on Azure I had described and guided you step by step on how to configure and test that scenario. I have had quite a few folks reach out to me and request that I do a similar writeup for … More ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with North South Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)

CPOC Series: ACI Service Chaining using Policy Based Redirect (PBR) for east-to-west traffic through an ASA FW

In this video we explore using Policy Based Redirects to identify either a subset or ALL traffic between EPGs and forcing that traffic to an external device, in our case, an ASA FW. In our case, our ACI Fabric is the L3GW for all traffic. With the PBR feature, we are going to use an … More CPOC Series: ACI Service Chaining using Policy Based Redirect (PBR) for east-to-west traffic through an ASA FW

CPOC Series: Achieving Segmentation in ACI by Attaching multiple EPGs to one Bridge Domain

In this video we explore the design practices of attaching multiple EPGs to a BD. There are several use-cases for this, including but not limited to: Application-centric design Not having to re-address servers that you want to split up (i.e., separating web servers from app servers from db servers in the same subnet) Compliance (i.e., … More CPOC Series: Achieving Segmentation in ACI by Attaching multiple EPGs to one Bridge Domain

CPOC Series: Using the Host-based routing feature in ACI to optimize ingress routing for MultiPod

What do you think of when you hear active/active as a requirement for datacenter connectivity? If its not the first thing on your mind, it’s in the top-5, and I’m talking about the need to influence ingress routing (i.e., keeping traffic local to where you endpoints reside). Whenever we have an active/active routing design, routes … More CPOC Series: Using the Host-based routing feature in ACI to optimize ingress routing for MultiPod

ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with Horizontal Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)

In this writeup I will show you how to configure a Multi-Node Service Graph in Azure using Cloud ACI.  We will insert multiple Service devices in-between the communication path of different workloads.   In addition one of the great values of this that you will immediately notice is the horizontal scaling of Firewalls.  Firewall Clustering is … More ACI/Cloud Extension Usage Primer (Azure) – Multi-Node Service Graph with Horizontal Firewall Scaling using vNET peering and hosting service devices in HUB vNET (overlay-2)