Cisco Platinum Learning Partner Logo

Implementation of a Cisco ACI

Setup of APIC and Fabric

Cisco Platinum Learning Partner Logo
The Application Centric Infrastructure (ACI) is an SDN concept from Cisco for the Nexus 9000 platform. As an extension of conventional SDN techniques, internal communication processes between application servers are also taken into account. The Application Policy Infrastructure Controller (APIC) exercises functional control over routing and resource distribution in the network. The position of the application processes is determined dynamically by the APIC and suitable policies are imported into the systems. The policies ensure optimal routing of data traffic between the server systems. In addition, the required bandwidth quotas are made available on the systems through suitable QoS reservations, depending on demand. ACI requires a pure spine-leaf architecture (Clos Design) for the cabling of the Nexus 9000 switches. This considerably simplifies the dynamic topology-based calculations on the APIC. Participants in the seminar will be familiar with the special features of the Nexus 9000 systems and their function in the context of ACI. They will be able to position ACI in relation to alternative approaches. Through practical exercises, participants will learn how to commission, configure and monitor an ACI environment. They acquire a deep understanding of the technology.

Course Contents

  • New terms with ACI: Application Profile and Endpoint Group
  • Network design for ACI
  • Tasks of the APIC
  • Fabric and External Access Policies
  • Interaction with the hypervisors
  • Tenants, VRFs and bridge domains
  • Concept of the contracts
  • Configuration and monitoring of ACI
  • External connections via L2/L3
  • Brief insight into further features: API, L4-L7 integration, AVE
  • Implementation between data centers: Multipod and multi-site
  • Practical exercises in the test network on current firmware

The detailed digital documentation package, consisting of an e-book and PDF, is included in the price of the course.

Premium Course Documents

In addition to the digital documentation package, the exclusive Premium Print Package is also available to you.

  • High-quality color prints of the ExperTeach documentation
  • Exclusive folder in an elegant design
  • Document pouch in backpack shape
  • Elegant LAMY ballpoint pen
  • Practical notepad
Premium Print
The Premium Print Package can be added during the ordering process for € 200,- plus VAT (only for classroom participation).
Request in-house training now

Target Group

The training is aimed at planners and administrators from the data center sector who want to learn about the possibilities of the Nexus 9000 switches and the Cisco Application Centric Infrastructure.

Knowledge Prerequisites

Prior knowledge of Data Center and Nexus Switches is desirable for successful participation. Concepts of virtualization should also be known, basic knowledge of VMware is ideal.
1 Konzepte der Application Centric Infrastructure
1.1 Viele neue Begriffe
1.2 Das Clos-Design
1.3 Die Hardware: Next Generation Data Center
1.3.1 Nexus 9500er Switch Series
1.3.2 Nexus 9300 Switch Series
1.3.3 FEX Support
1.4 Application Policy Infrastructure Controller
1.4.1 Verteilung der Shards im APIC Cluster
1.4.2 Mini ACI Fabric und Virtual APICs
1.4.3 Stretched Fabric
1.4.4 ACI Multi-Pod
1.4.5 Remote Leaf
1.4.6 Multi-Site Controller
1.4.7 Virtual POD und Cloud APIC
1.5 Overlay-Netze
1.5.1 Overlay mit VXLANs
1.5.2 Underlay Network mit VTEPs und IS-IS
1.5.3 Forwarding in der Fabric
1.6 Multitenancy
1.6.1 Abbildung der klassischen Begriffe: VLANs
1.6.2 Networking
1.6.3 Application Profiles
1.7 ACI Policy Model
   
2 Setup der Fabric
2.1 Inbetriebnahme des APIC
2.1.1 BIOS und CIMC
2.1.2 Setup des APIC (1/3)
2.1.3 Zugriffsmöglichkeiten auf den APIC
2.2 Discovery der Fabric
2.2.1 Überprüfung des Controllers
2.2.2 Discovery der Nodes
2.2.3 Registrierung im Fabric-Menü
2.2.4 Überprüfung der Nodes
2.2.5 Manuelle Konfiguration der Nodes
2.2.6 Das Discovery im CLI
2.3 Einrichten der Management-Infrastruktur
2.3.1 Out-of-Band-Management
2.3.2 Inband-Management
2.4 Grundeinrichtung der Fabric
2.4.1 BGP Route Reflektoren
2.4.2 Zeit- und NTP-Konfiguration
2.4.3 Domain Name System
2.4.4 Best Practice für globale Einstellungen
2.5 System Settings
2.5.1 Banner-Konfiguration
2.5.2 Port Tracking und Endpoint Controls
2.6 Arbeiten mit den Fabric Policies
2.6.1 SNMP-Konfiguration
2.6.2 Protokolle für den Management-Zugriff
2.6.3 Global Policies
2.7 Einrichten des Monitoring
   
3 User-Konfiguration und Wartungsaufgaben
3.1 User Management
3.1.1 Security Management
3.1.2 Lokale User und Rollen
3.1.3 Remote Users und Login Domains
3.1.4 Login Domains und Default Authentication
3.1.5 Überwachung der User
3.1.6 Public Key Management und CA
3.2 Wartungsarbeiten
3.2.1 Einrichten von Remote Locations
3.2.2 Arbeiten mit Konfigurationen
3.2.3 Sammeln von Support-Informationen
3.2.4 Firmware-Upgrades
   
4 Konfiguration durch Policies
4.1 Unterschiedliche Policies
4.2 Konfiguration der Switch-Parameter
4.2.1 Switch Policies
4.2.2 Switch Policy Groups
4.2.3 Switch Profiles
4.2.4 Die Switch Profiles im Einsatz
4.3 Konfiguration der Interfaces
4.3.1 Interface Policies
4.3.2 Interface Policy Groups
4.3.3 Interface Profiles
4.3.4 Overrides
4.3.5 Arbeiten mit Interface Profiles - Beispiele
4.4 Pools und Domains
4.4.1 Die verschiedenen Pools
4.4.2 Physical Domains
4.4.3 External Domains
4.4.4 Virtual Domains
4.5 Global Policies
4.5.1 Attachable Access Entity Profile
4.5.2 Global Access Policies
   
5 Tenants und Contracts
5.1 Tenants
5.1.1 Struktur innerhalb des Tenants
5.1.2 Konfiguration eines Tenant
5.1.3 Der Tenant im APIC CLI
5.2 Networking
5.2.1 Anlegen von VRFs
5.2.2 Bridge Domains
5.2.3 Networking Parameter im CLI
5.3 Application Profiles
5.3.1 Konfiguration von Application EPGs
5.3.2 Zuweisung der Domains
5.4 Kommunikation im Tenant
5.4.1 IP-Adressen im Tenant
5.4.2 Anzeige der Endpoints
5.4.3 VLANs und VRFs
5.5 DHCP Relay
5.5.1 Einrichten eines DHCP Providers
5.5.2 Zuweisen des DHCP Relay Labels
5.6 Contracts, Subjects und Filter
5.6.1 Filter
5.6.2 Contracts
5.6.3 Kommunikation zwischen EPGs
5.6.4 Uni- und Bidirektionale Contract Subjects
5.6.5 EPG Contract Master, vzAny und Preferred Group
5.6.6 Kommunikation zwischen VRFs
5.6.7 Contract Labels und Subject Labels
5.6.8 Taboo Contracts
5.6.9 Contract Subjects mit Deny
   
6 Erweiterte Konfiguration
6.1 Anbindung von externen L2-Netzen
6.1.1 Mapping eines VLANs auf eine EPG
6.1.2 External Bridged Networks
6.2 Externe Layer-3-Netzwerke
6.2.1 Grundeinstellungen im L3 External Network
6.2.2 Kommunikation über Verträge
6.2.3 Arbeiten mit Routing-Protokollen
6.2.4 Nutzung von BFD
6.2.5 Anbindung der Bridge Domain an das L3 External Network
6.2.6 Monitoring der L3-Konfiguration
6.3 Arbeiten mit ACI Virtual Edge (AVE)
6.3.1 Struktur des ACI Virtual Edge
6.3.2 Voraussetzungen für AVE
6.3.3 Einrichten des AVE
6.3.4 Installation der AVE VMs
6.4 Microsegmentation
6.5 L4-L7-Integration
6.5.1 Anbindung eines L4-L7-Service
6.5.2 Anlegen des L4-L7 Device
6.5.3 Service Graphs Templates
6.5.4 Erzeugen eines Service Graph
6.6 Nutzung der Northbound API
6.6.1 REST API
6.6.2 XML und JSON
6.6.3 Arbeiten mit Postman
6.6.4 Verwendung von Python und ARYA
   
7 Monitoring und Troubleshooting
7.1 Monitoring der ACI Fabric
7.1.1 Health Score
7.1.2 Nachverfolgung von Fehlern
7.1.3 Nutzung von Statistiken
7.2 Troubleshooting Tools
7.2.1 End Point Tracker
7.2.2 Visibility & Troubleshooting
7.2.3 Atomic Counters und Latency
7.2.4 Digital Monitoring Statistics
7.2.5 Einrichten eines SPAN-Ports
   
A Abkürzungsverzeichnis
   
B Befehle

Classroom training

Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!

Online training

You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.

Tailor-made courses

You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
Request in-house training now
PDF SymbolYou can find the complete description of this course with dates and prices ready for download at as PDF.

The Application Centric Infrastructure (ACI) is an SDN concept from Cisco for the Nexus 9000 platform. As an extension of conventional SDN techniques, internal communication processes between application servers are also taken into account. The Application Policy Infrastructure Controller (APIC) exercises functional control over routing and resource distribution in the network. The position of the application processes is determined dynamically by the APIC and suitable policies are imported into the systems. The policies ensure optimal routing of data traffic between the server systems. In addition, the required bandwidth quotas are made available on the systems through suitable QoS reservations, depending on demand. ACI requires a pure spine-leaf architecture (Clos Design) for the cabling of the Nexus 9000 switches. This considerably simplifies the dynamic topology-based calculations on the APIC. Participants in the seminar will be familiar with the special features of the Nexus 9000 systems and their function in the context of ACI. They will be able to position ACI in relation to alternative approaches. Through practical exercises, participants will learn how to commission, configure and monitor an ACI environment. They acquire a deep understanding of the technology.

Course Contents

  • New terms with ACI: Application Profile and Endpoint Group
  • Network design for ACI
  • Tasks of the APIC
  • Fabric and External Access Policies
  • Interaction with the hypervisors
  • Tenants, VRFs and bridge domains
  • Concept of the contracts
  • Configuration and monitoring of ACI
  • External connections via L2/L3
  • Brief insight into further features: API, L4-L7 integration, AVE
  • Implementation between data centers: Multipod and multi-site
  • Practical exercises in the test network on current firmware

The detailed digital documentation package, consisting of an e-book and PDF, is included in the price of the course.

Premium Course Documents

In addition to the digital documentation package, the exclusive Premium Print Package is also available to you.

  • High-quality color prints of the ExperTeach documentation
  • Exclusive folder in an elegant design
  • Document pouch in backpack shape
  • Elegant LAMY ballpoint pen
  • Practical notepad
Premium Print
The Premium Print Package can be added during the ordering process for € 200,- plus VAT (only for classroom participation).
Request in-house training now

Target Group

The training is aimed at planners and administrators from the data center sector who want to learn about the possibilities of the Nexus 9000 switches and the Cisco Application Centric Infrastructure.

Knowledge Prerequisites

Prior knowledge of Data Center and Nexus Switches is desirable for successful participation. Concepts of virtualization should also be known, basic knowledge of VMware is ideal.

1 Konzepte der Application Centric Infrastructure
1.1 Viele neue Begriffe
1.2 Das Clos-Design
1.3 Die Hardware: Next Generation Data Center
1.3.1 Nexus 9500er Switch Series
1.3.2 Nexus 9300 Switch Series
1.3.3 FEX Support
1.4 Application Policy Infrastructure Controller
1.4.1 Verteilung der Shards im APIC Cluster
1.4.2 Mini ACI Fabric und Virtual APICs
1.4.3 Stretched Fabric
1.4.4 ACI Multi-Pod
1.4.5 Remote Leaf
1.4.6 Multi-Site Controller
1.4.7 Virtual POD und Cloud APIC
1.5 Overlay-Netze
1.5.1 Overlay mit VXLANs
1.5.2 Underlay Network mit VTEPs und IS-IS
1.5.3 Forwarding in der Fabric
1.6 Multitenancy
1.6.1 Abbildung der klassischen Begriffe: VLANs
1.6.2 Networking
1.6.3 Application Profiles
1.7 ACI Policy Model
   
2 Setup der Fabric
2.1 Inbetriebnahme des APIC
2.1.1 BIOS und CIMC
2.1.2 Setup des APIC (1/3)
2.1.3 Zugriffsmöglichkeiten auf den APIC
2.2 Discovery der Fabric
2.2.1 Überprüfung des Controllers
2.2.2 Discovery der Nodes
2.2.3 Registrierung im Fabric-Menü
2.2.4 Überprüfung der Nodes
2.2.5 Manuelle Konfiguration der Nodes
2.2.6 Das Discovery im CLI
2.3 Einrichten der Management-Infrastruktur
2.3.1 Out-of-Band-Management
2.3.2 Inband-Management
2.4 Grundeinrichtung der Fabric
2.4.1 BGP Route Reflektoren
2.4.2 Zeit- und NTP-Konfiguration
2.4.3 Domain Name System
2.4.4 Best Practice für globale Einstellungen
2.5 System Settings
2.5.1 Banner-Konfiguration
2.5.2 Port Tracking und Endpoint Controls
2.6 Arbeiten mit den Fabric Policies
2.6.1 SNMP-Konfiguration
2.6.2 Protokolle für den Management-Zugriff
2.6.3 Global Policies
2.7 Einrichten des Monitoring
   
3 User-Konfiguration und Wartungsaufgaben
3.1 User Management
3.1.1 Security Management
3.1.2 Lokale User und Rollen
3.1.3 Remote Users und Login Domains
3.1.4 Login Domains und Default Authentication
3.1.5 Überwachung der User
3.1.6 Public Key Management und CA
3.2 Wartungsarbeiten
3.2.1 Einrichten von Remote Locations
3.2.2 Arbeiten mit Konfigurationen
3.2.3 Sammeln von Support-Informationen
3.2.4 Firmware-Upgrades
   
4 Konfiguration durch Policies
4.1 Unterschiedliche Policies
4.2 Konfiguration der Switch-Parameter
4.2.1 Switch Policies
4.2.2 Switch Policy Groups
4.2.3 Switch Profiles
4.2.4 Die Switch Profiles im Einsatz
4.3 Konfiguration der Interfaces
4.3.1 Interface Policies
4.3.2 Interface Policy Groups
4.3.3 Interface Profiles
4.3.4 Overrides
4.3.5 Arbeiten mit Interface Profiles - Beispiele
4.4 Pools und Domains
4.4.1 Die verschiedenen Pools
4.4.2 Physical Domains
4.4.3 External Domains
4.4.4 Virtual Domains
4.5 Global Policies
4.5.1 Attachable Access Entity Profile
4.5.2 Global Access Policies
   
5 Tenants und Contracts
5.1 Tenants
5.1.1 Struktur innerhalb des Tenants
5.1.2 Konfiguration eines Tenant
5.1.3 Der Tenant im APIC CLI
5.2 Networking
5.2.1 Anlegen von VRFs
5.2.2 Bridge Domains
5.2.3 Networking Parameter im CLI
5.3 Application Profiles
5.3.1 Konfiguration von Application EPGs
5.3.2 Zuweisung der Domains
5.4 Kommunikation im Tenant
5.4.1 IP-Adressen im Tenant
5.4.2 Anzeige der Endpoints
5.4.3 VLANs und VRFs
5.5 DHCP Relay
5.5.1 Einrichten eines DHCP Providers
5.5.2 Zuweisen des DHCP Relay Labels
5.6 Contracts, Subjects und Filter
5.6.1 Filter
5.6.2 Contracts
5.6.3 Kommunikation zwischen EPGs
5.6.4 Uni- und Bidirektionale Contract Subjects
5.6.5 EPG Contract Master, vzAny und Preferred Group
5.6.6 Kommunikation zwischen VRFs
5.6.7 Contract Labels und Subject Labels
5.6.8 Taboo Contracts
5.6.9 Contract Subjects mit Deny
   
6 Erweiterte Konfiguration
6.1 Anbindung von externen L2-Netzen
6.1.1 Mapping eines VLANs auf eine EPG
6.1.2 External Bridged Networks
6.2 Externe Layer-3-Netzwerke
6.2.1 Grundeinstellungen im L3 External Network
6.2.2 Kommunikation über Verträge
6.2.3 Arbeiten mit Routing-Protokollen
6.2.4 Nutzung von BFD
6.2.5 Anbindung der Bridge Domain an das L3 External Network
6.2.6 Monitoring der L3-Konfiguration
6.3 Arbeiten mit ACI Virtual Edge (AVE)
6.3.1 Struktur des ACI Virtual Edge
6.3.2 Voraussetzungen für AVE
6.3.3 Einrichten des AVE
6.3.4 Installation der AVE VMs
6.4 Microsegmentation
6.5 L4-L7-Integration
6.5.1 Anbindung eines L4-L7-Service
6.5.2 Anlegen des L4-L7 Device
6.5.3 Service Graphs Templates
6.5.4 Erzeugen eines Service Graph
6.6 Nutzung der Northbound API
6.6.1 REST API
6.6.2 XML und JSON
6.6.3 Arbeiten mit Postman
6.6.4 Verwendung von Python und ARYA
   
7 Monitoring und Troubleshooting
7.1 Monitoring der ACI Fabric
7.1.1 Health Score
7.1.2 Nachverfolgung von Fehlern
7.1.3 Nutzung von Statistiken
7.2 Troubleshooting Tools
7.2.1 End Point Tracker
7.2.2 Visibility & Troubleshooting
7.2.3 Atomic Counters und Latency
7.2.4 Digital Monitoring Statistics
7.2.5 Einrichten eines SPAN-Ports
   
A Abkürzungsverzeichnis
   
B Befehle

Classroom training

Do you prefer the classic training method? A course in one of our Training Centers, with a competent trainer and the direct exchange between all course participants? Then you should book one of our classroom training dates!

Online training

You wish to attend a course in online mode? We offer you online course dates for this course topic. To attend these seminars, you need to have a PC with Internet access (minimum data rate 1Mbps), a headset when working via VoIP and optionally a camera. For further information and technical recommendations, please refer to.

Tailor-made courses

You need a special course for your team? In addition to our standard offer, we will also support you in creating your customized courses, which precisely meet your individual demands. We will be glad to consult you and create an individual offer for you.
Request in-house training now

PDF SymbolYou can find the complete description of this course with dates and prices ready for download at as PDF.