<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.fastlanetraining.ca/css/xml-course.xsl"?><course productid="32284" language="en" source="https://portal.fastlanetraining.ca/minose/xml-course/ot-acies" lastchanged="2023-03-07T10:14:17-05:00" parent="https://portal.fastlanetraining.ca/minose/xml-courses"><title>The ACI Elite Series</title><productcode>ACIES</productcode><vendorcode>OT</vendorcode><vendorname>Other</vendorname><fullproductcode>OT-ACIES</fullproductcode><version>1.0</version><objective>&lt;ul&gt;
&lt;li&gt;Describe ACI components and policy model&lt;/li&gt;&lt;li&gt;Explain ACI packet forwarding&lt;/li&gt;&lt;li&gt;Describe ACI fabric configuration&lt;/li&gt;&lt;li&gt;Describe ACI logical constructs&lt;/li&gt;&lt;li&gt;Explain how ACI uses contracts to allow for secure communication between endpoints&lt;/li&gt;&lt;li&gt;Explain how ACI connects to other switched and routed networks&lt;/li&gt;&lt;li&gt;Explain how to troubleshoot an ACI fabric&lt;/li&gt;&lt;li&gt;Describe multi-site and multi-pod solutions, and how they fit in a multi-DC/multi-cloud design&lt;/li&gt;&lt;/ul&gt;</objective><audience>&lt;p&gt;This ACI Elite Series will provide value for anyone deploying or operating an ACI fabric. However, some topics will be more relevant to specific audience:
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sessions 1, 7, 8, 9, 10, 12, 13, and 14 are more focused for Architects or Engineers completing design work&lt;/li&gt;&lt;li&gt;Sessions 2, 3, 4, 5, 6, and 11 are more focused for operations teams&lt;/li&gt;&lt;/ul&gt;</audience><outline>&lt;h4&gt;Session 1 - ACI Overview&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;What is ACI&lt;/li&gt;&lt;li&gt;ACIs benefits&lt;/li&gt;&lt;li&gt;Overview of Switch and APIC models APIC Architecture Fabric&lt;/li&gt;&lt;li&gt;Bring up process&lt;/li&gt;&lt;li&gt;ACI Object Model&lt;/li&gt;&lt;li&gt;ACI MGMT&lt;ul&gt;
&lt;li&gt;RBAC&lt;/li&gt;&lt;li&gt;Syslog&lt;/li&gt;&lt;li&gt;SNMP&lt;/li&gt;&lt;li&gt;Upgrade Process&lt;/li&gt;&lt;li&gt;BGP Policy&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Instructor demo GUI Overview&lt;/li&gt;&lt;li&gt;Instructor demo Intro to CLI&lt;/li&gt;&lt;li&gt;Creating Users and assign Permissions Software&lt;/li&gt;&lt;li&gt;Upgrades&lt;/li&gt;&lt;li&gt;Syslog, SNMP and config rollbacks&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 2 - Fabric Forwarding&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;VXLAN refresher&lt;/li&gt;&lt;li&gt;Understanding Bridge Domains&lt;ul&gt;
&lt;li&gt;Bridge Domain as a layer 2 boundary&lt;/li&gt;&lt;li&gt;Difference between VLANs and Bridge Domains&lt;/li&gt;&lt;li&gt;Bridge Domain configuration knobs&lt;ul&gt;
&lt;li&gt;Limit Learning to IP subnet&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Encapsulation and multicast group&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;COOP&lt;ul&gt;
&lt;li&gt;Oracles and Citizens&lt;/li&gt;&lt;li&gt;Endpoint tables&lt;/li&gt;&lt;li&gt;Lookup process&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Layer2 and Layer3 forwarding&lt;ul&gt;
&lt;li&gt;ARP handling packet walk&lt;/li&gt;&lt;li&gt;L2 packet walk&lt;/li&gt;&lt;li&gt;L3 packet walk&lt;/li&gt;&lt;li&gt;BUM traffic packet walk&lt;/li&gt;&lt;li&gt;VXLAN Encapsulations&lt;ul&gt;
&lt;li&gt;Intro to Fd_VLANs and BD_VLANs&lt;/li&gt;&lt;li&gt;VRF encapsulation&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;EP move and bounce entries&lt;/li&gt;&lt;li&gt;Rogue endpoint detection&lt;/li&gt;&lt;li&gt;Silent hosts&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Endpoint table vs Mac and Routing Table&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;
&lt;strong&gt;
Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Intro to endpoint reachability troubleshooting&lt;/li&gt;&lt;li&gt;Understanding show endpoint command&lt;/li&gt;&lt;li&gt;Validate COOP entries (GUI and CLI)&lt;/li&gt;&lt;li&gt;Using iPing, ELAM and Ftriage (App not CLI)&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 3 - Fabric Configuration Part 1&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview of interface configurations&lt;ul&gt;
&lt;li&gt;Physical and VMM domains overview&lt;ul&gt;
&lt;li&gt;Deployment immediacy (VMM)&lt;/li&gt;&lt;li&gt;Resolution immediacy (VMM)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;VLAN Pools&lt;ul&gt;
&lt;li&gt;Static and Dynamic Pools&lt;/li&gt;&lt;li&gt;Base encap value&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;AEPs&lt;ul&gt;
&lt;li&gt;Used as a way to tie VLANs to an Interface&lt;/li&gt;&lt;li&gt;Used to define EPG membership&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Policy Groups&lt;/li&gt;&lt;li&gt;Interface Profiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Overview of switch configurations&lt;ul&gt;
&lt;li&gt;VPC in ACI&lt;/li&gt;&lt;li&gt;Switch Profiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;VLANs in the ACI world&lt;ul&gt;
&lt;li&gt;P I, HW, Access Encap, BD and FD&lt;/li&gt;&lt;li&gt;Physical Domain, AEP and VLAN Pool relationship to FD_VLAN.and VXLAN encap&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs: &lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a physical Domain to connect endpoints to the ACI Fabric&lt;ul&gt;
&lt;li&gt;Create VLAN Pool and AEP&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Create a VMM domain to connect endpoints to the ACI fabric&lt;ul&gt;
&lt;li&gt;Create VLAN Pool and AEP&lt;/li&gt;&lt;li&gt;Create VMM integration&lt;/li&gt;&lt;li&gt;Create VPCs explicit protection groups&lt;/li&gt;&lt;li&gt;Create Interface Profiles and Policy Groups&lt;/li&gt;&lt;li&gt;Create Switch Profiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Understanding the output&lt;ul&gt;
&lt;li&gt;Show VLAN brief&lt;/li&gt;&lt;li&gt;Show VLAN extended&lt;/li&gt;&lt;li&gt;Show system internal eltmc info VLAN brief (vsh_lc shell)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 4 - Fabric Configuration Part 2&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lectures:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Overview of interface configurations&lt;/li&gt;&lt;li&gt;Physical and VMM domains overview&lt;ul&gt;
&lt;li&gt;Deployment immediacy (VMM)&lt;/li&gt;&lt;li&gt;Resolution immediacy (VMM)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;VLAN Pools&lt;ul&gt;
&lt;li&gt;Static and Dynamic Pools&lt;/li&gt;&lt;li&gt;Base encap value&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;AEPs&lt;ul&gt;
&lt;li&gt;Used as a way to tie VLANs to an Interface&lt;/li&gt;&lt;li&gt;Used to define EPG membership Policy Groups, Interface Profiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Overview of switch configurations&lt;ul&gt;
&lt;li&gt;VPC in ACI&lt;/li&gt;&lt;li&gt;Switch Profiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;VLANs in the ACI world&lt;ul&gt;
&lt;li&gt;P I, HW, Access Encap, BD and FD&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Physical Domain, AEP and VLAN Pool relationship to FD_VLAN and VXLAN encap&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a physical Domain to connect endpoints to the ACI Fabric&lt;ul&gt;
&lt;li&gt;Create VLAN Pool and AEP&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Create a VMM domain to connect endpoints to the ACI fabric&lt;ul&gt;
&lt;li&gt;Create VLAN Pool and AEP&lt;/li&gt;&lt;li&gt;Create VMM integration&lt;/li&gt;&lt;li&gt;Create VPCs explicit protection groups&lt;/li&gt;&lt;li&gt;Create Interface Profiles and Policy Groups&lt;/li&gt;&lt;li&gt;Create SwitchProfiles&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Understanding the output&lt;ul&gt;
&lt;li&gt;Show VLAN brief&lt;/li&gt;&lt;li&gt;Show VLAN extended&lt;/li&gt;&lt;li&gt;Show system internal eltmc info VLAN brief (vsh_lc shell)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 5 - ACI Logical Constructs Part 1&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tenants&lt;/li&gt;&lt;li&gt;VRFs&lt;/li&gt;&lt;li&gt;Bridge Domains&lt;/li&gt;&lt;li&gt;Application Profiles&lt;/li&gt;&lt;li&gt;EPGs and Endpoint Security Groups&lt;ul&gt;
&lt;li&gt;VMM and Physical Domains&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Intro to Contracts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a tenant&lt;/li&gt;&lt;li&gt;Create an Application Profile&lt;/li&gt;&lt;li&gt;Create a set of EPGs and establish L2 and L3 connectivity between endpoints&lt;ul&gt;
&lt;li&gt;Create required BDs, EPGs and Contracts&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 6 - ACI Logical Constructs Part 2&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Tenants&lt;/li&gt;&lt;li&gt;VRFs&lt;/li&gt;&lt;li&gt;Bridge Domains&lt;/li&gt;&lt;li&gt;Application Profiles&lt;/li&gt;&lt;li&gt;EPGs and Endpoint Security Groups&lt;ul&gt;
&lt;li&gt;VMM and Physical Domains&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Intro to Contracts&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a tenant&lt;/li&gt;&lt;li&gt;Create an Application Profile&lt;/li&gt;&lt;li&gt;Create a set of EPGs and establish L2 and L3 connectivity between endpoints&lt;ul&gt;
&lt;li&gt;Create required BDs, EPGs and Contracts&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 7 - Contracts&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Contract Scope&lt;/li&gt;&lt;li&gt;Subjects&lt;/li&gt;&lt;li&gt;Filters&lt;ul&gt;
&lt;li&gt;Directives (Log and Policy Compression)&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Verifying L2 and L3 permit and denies from the GUI Subject Labels&lt;ul&gt;
&lt;li&gt;Apply both ways and reverse filter ports&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;EPG Labels Deny&lt;/li&gt;&lt;li&gt;Contracts&lt;ul&gt;
&lt;li&gt;Taboo Contracts&lt;/li&gt;&lt;li&gt;Regular contracts with Deny Filter&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;VRF Enforced and Unenforced&lt;/li&gt;&lt;li&gt;Preferred Group&lt;/li&gt;&lt;li&gt;VZ_ANY&lt;/li&gt;&lt;li&gt;Consumed contract interfaces (Intro to leaking)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enable EPG to EPG communication using Subject Labels and EPG Labels&lt;/li&gt;&lt;li&gt;Enable EPG to EPG communication using Preferred Group and VZ_Any VRF options&lt;/li&gt;&lt;li&gt;Block specific traffic using Taboo contracts and deny filters&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 8 - External Connectivity Part 1&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Layer 2 Connectivity&lt;ul&gt;
&lt;li&gt;Understanding L2Outs&lt;/li&gt;&lt;li&gt;Understanding VLANs on ACI&lt;/li&gt;&lt;li&gt;Understanding EPG extensions&lt;/li&gt;&lt;li&gt;Unicast Routing option on Bridge Domain for migration&lt;/li&gt;&lt;li&gt;Dual homing Layer 2 connectivity&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Layer 3 Connectivity&lt;ul&gt;
&lt;li&gt;L3Out Building Blocks&lt;/li&gt;&lt;li&gt;Single L3Outs with Multiple Node Profiles vs Multiple L3Outs with single Node Profile&lt;ul&gt;
&lt;li&gt;Traffic Shaping and traffic flow&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Layer 3 VPC&lt;ul&gt;
&lt;li&gt;Special configuration for HA L4-L7 Devices&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Understanding Subnet options for Ext-EPG&lt;/li&gt;&lt;li&gt;Advertising routes&lt;ul&gt;
&lt;li&gt;Mapping L3Out to Bridge Domain&lt;/li&gt;&lt;li&gt;Using Route Maps&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Shared L3Outs&lt;ul&gt;
&lt;li&gt;VRF Leaking overview and verification&lt;/li&gt;&lt;li&gt;Shared L3Out on Common Tenant&lt;/li&gt;&lt;li&gt;Shared L3Out on different tenants&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Transit Routing&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a L2Out and consume a GW outside of ACI&lt;/li&gt;&lt;li&gt;Replicate the config using an EPG extension&lt;/li&gt;&lt;li&gt;Create a local L3Out&lt;/li&gt;&lt;li&gt;Create a Shared L3Out&lt;/li&gt;&lt;li&gt;Advertise routes not owned by ACI&lt;/li&gt;&lt;li&gt;Configure an L3out to be preferred over other L3Outs&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 9 - External Connectivity Part 2&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Layer 2 Connectivity&lt;ul&gt;
&lt;li&gt;Understanding L2Outs&lt;/li&gt;&lt;li&gt;Understanding VLANs on ACI&lt;/li&gt;&lt;li&gt;Understanding EPG extensions&lt;/li&gt;&lt;li&gt;Unicast Routing option on Bridge Domain for migration&lt;/li&gt;&lt;li&gt;Dual homing Layer 2 connectivity&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Layer 3 Connectivity&lt;ul&gt;
&lt;li&gt;L3Out Building Blocks&lt;/li&gt;&lt;li&gt;Single L3Outs with Multiple Node Profiles vs Multiple L3Outs with single Node Profile&lt;ul&gt;
&lt;li&gt;Traffic Shaping and traffic flow&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Layer 3 VPC&lt;ul&gt;
&lt;li&gt;Special configuration for HA L4-L7 Devices&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Understanding Subnet options for Ext-EPG&lt;/li&gt;&lt;li&gt;Advertising routes&lt;ul&gt;
&lt;li&gt;Mapping L3Out to Bridge Domain&lt;/li&gt;&lt;li&gt;Using Route Maps&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Shared L3Outs&lt;ul&gt;
&lt;li&gt;VRF Leaking overview and verification&lt;/li&gt;&lt;li&gt;Shared L3Out on Common Tenant&lt;/li&gt;&lt;li&gt;Shared L3Out on different tenants&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Transit Routing&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a L2Out and consume a GW outside of ACI&lt;/li&gt;&lt;li&gt;Replicate the config using an EPG extension&lt;/li&gt;&lt;li&gt;Create a local L3Out&lt;/li&gt;&lt;li&gt;Create a Shared L3Out&lt;/li&gt;&lt;li&gt;Advertise routes not owned by ACI&lt;/li&gt;&lt;li&gt;Configure an L3out to be preferred over other L3Outs&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 10 - Deployment Models and DevOps&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Naming Convention&lt;/li&gt;&lt;li&gt;App Centric and Network Centric&lt;ul&gt;
&lt;li&gt;EPG to Bridge Domain to VLAN and Subnet relationship&lt;/li&gt;&lt;li&gt;Generic VLAN/Subnet to App Driven VLAN/Subnet&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Whitelisting, Blacklisting, and Graylisting&lt;/li&gt;&lt;li&gt;Benefits and Drawbacks&lt;/li&gt;&lt;li&gt;Intro to Automation&lt;ul&gt;
&lt;li&gt;Moquery&lt;/li&gt;&lt;li&gt;API inspector and postman&lt;/li&gt;&lt;li&gt;Python&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Cobra SDK&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Recreating our lab topology thru Python and Postman&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 11 - Troubleshooting&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Different CLI shells&lt;/li&gt;&lt;li&gt;Common troubleshooting commands Structure to&lt;/li&gt;&lt;li&gt;ACI troubleshooting&lt;/li&gt;&lt;li&gt;Elam and fTriage CLI&lt;/li&gt;&lt;li&gt;Understanding how to use show zoning rule&lt;/li&gt;&lt;li&gt;Common faults and mistakes&lt;/li&gt;&lt;li&gt;L3Out debugging in the ACI world&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use the discussed tools to troubleshoot connectivity issues between endpoints connected to the ACI fabric and end-points connected via L3Out&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 12 - Multi-Site and Multi-Pod Part 1&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Active/Active, HA, Metro, and DR&lt;ul&gt;
&lt;li&gt;What it means&lt;/li&gt;&lt;li&gt;How to choose the correct fit based on business requirements&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Multi-pod&lt;ul&gt;
&lt;li&gt;Components&lt;/li&gt;&lt;li&gt;Requirements&lt;/li&gt;&lt;li&gt;Fabric forwarding between Pods&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Multi-site&lt;ul&gt;
&lt;li&gt;Components&lt;/li&gt;&lt;li&gt;Requirements&lt;/li&gt;&lt;li&gt;Fabric forwarding between sites&lt;/li&gt;&lt;li&gt;Stretched vs non-stretched&lt;/li&gt;&lt;li&gt;Understanding Schema&lt;/li&gt;&lt;li&gt;Intersite L3Outs&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Azure and AWS&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Verifying a multi-pod deployment&lt;/li&gt;&lt;li&gt;Deploying Tenants using MSO&lt;ul&gt;
&lt;li&gt;Configure App Profile and EPGs from MSO&lt;/li&gt;&lt;li&gt;Create Local and Stretched Bridge Domains&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 13 - Multi-Site and Multi-Pod Part 2&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Active/Active, HA, Metro, and DR&lt;ul&gt;
&lt;li&gt;What it means&lt;/li&gt;&lt;li&gt;How to choose the correct fit based on business requirements&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Multi-pod&lt;ul&gt;
&lt;li&gt;Components&lt;/li&gt;&lt;li&gt;Requirements&lt;/li&gt;&lt;li&gt;Fabric forwarding between Pods&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Multi-site&lt;ul&gt;
&lt;li&gt;Components&lt;/li&gt;&lt;li&gt;Requirements&lt;/li&gt;&lt;li&gt;Fabric forwarding between sites&lt;/li&gt;&lt;li&gt;Stretched vs non-stretched&lt;/li&gt;&lt;li&gt;Understanding Schema&lt;/li&gt;&lt;li&gt;Intersite L3Outs&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Azure and AWS&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Verifying a Multi-pod deployment&lt;/li&gt;&lt;li&gt;Deploying Tenants using MSO&lt;ul&gt;
&lt;li&gt;Configure App Profile and EPGs from MSO&lt;/li&gt;&lt;li&gt;Create Local and Stretched Bridge Domains&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h4&gt;Session 14 - Design and Migration Considerations&lt;/h4&gt;&lt;p&gt;
&lt;strong&gt;Lecture:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Integrating ACI to legacy environments Migration Steps&lt;/li&gt;&lt;li&gt;Migration considerations&lt;/li&gt;&lt;li&gt;FW Considerations&lt;ul&gt;
&lt;li&gt;Where do we place the GWs?&lt;/li&gt;&lt;li&gt;Designing based on Zones&lt;/li&gt;&lt;li&gt;To Service Graph or not to Service Graph&lt;/li&gt;&lt;li&gt;DMZ inside of ACI vs DMZ outside&lt;/li&gt;&lt;li&gt;Understanding inbound and outbound traffic flow for multi-DC solutions&lt;/li&gt;&lt;li&gt;Multi-cloud considerations&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;LB considerations&lt;ul&gt;
&lt;li&gt;Single or Multi-hop&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;GSLB/GTM requirements for multi-DC solutions&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Labs:&lt;/strong&gt;
&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create a DMZ structure inside of ACI connecting to FWs and LBs&lt;/li&gt;&lt;li&gt;Test Connectivity from the outside world&lt;/li&gt;&lt;/ul&gt;</outline><objective_plain>- Describe ACI components and policy model
- Explain ACI packet forwarding
- Describe ACI fabric configuration
- Describe ACI logical constructs
- Explain how ACI uses contracts to allow for secure communication between endpoints
- Explain how ACI connects to other switched and routed networks
- Explain how to troubleshoot an ACI fabric
- Describe multi-site and multi-pod solutions, and how they fit in a multi-DC/multi-cloud design</objective_plain><audience_plain>This ACI Elite Series will provide value for anyone deploying or operating an ACI fabric. However, some topics will be more relevant to specific audience:



- Sessions 1, 7, 8, 9, 10, 12, 13, and 14 are more focused for Architects or Engineers completing design work
- Sessions 2, 3, 4, 5, 6, and 11 are more focused for operations teams</audience_plain><outline_plain>Session 1 - ACI Overview


Lecture



- What is ACI
- ACIs benefits
- Overview of Switch and APIC models APIC Architecture Fabric
- Bring up process
- ACI Object Model
- ACI MGMT
- RBAC
- Syslog
- SNMP
- Upgrade Process
- BGP Policy
Labs



- Instructor demo GUI Overview
- Instructor demo Intro to CLI
- Creating Users and assign Permissions Software
- Upgrades
- Syslog, SNMP and config rollbacks
Session 2 - Fabric Forwarding


Lecture



- VXLAN refresher
- Understanding Bridge Domains
- Bridge Domain as a layer 2 boundary
- Difference between VLANs and Bridge Domains
- Bridge Domain configuration knobs
- Limit Learning to IP subnet
- Encapsulation and multicast group
- COOP
- Oracles and Citizens
- Endpoint tables
- Lookup process
- Layer2 and Layer3 forwarding
- ARP handling packet walk
- L2 packet walk
- L3 packet walk
- BUM traffic packet walk
- VXLAN Encapsulations
- Intro to Fd_VLANs and BD_VLANs
- VRF encapsulation
- EP move and bounce entries
- Rogue endpoint detection
- Silent hosts
- Endpoint table vs Mac and Routing Table


Labs:



- Intro to endpoint reachability troubleshooting
- Understanding show endpoint command
- Validate COOP entries (GUI and CLI)
- Using iPing, ELAM and Ftriage (App not CLI)
Session 3 - Fabric Configuration Part 1


Lecture:



- Overview of interface configurations
- Physical and VMM domains overview
- Deployment immediacy (VMM)
- Resolution immediacy (VMM)
- VLAN Pools
- Static and Dynamic Pools
- Base encap value
- AEPs
- Used as a way to tie VLANs to an Interface
- Used to define EPG membership
- Policy Groups
- Interface Profiles
- Overview of switch configurations
- VPC in ACI
- Switch Profiles
- VLANs in the ACI world
- P I, HW, Access Encap, BD and FD
- Physical Domain, AEP and VLAN Pool relationship to FD_VLAN.and VXLAN encap
Labs: 



- Create a physical Domain to connect endpoints to the ACI Fabric
- Create VLAN Pool and AEP
- Create a VMM domain to connect endpoints to the ACI fabric
- Create VLAN Pool and AEP
- Create VMM integration
- Create VPCs explicit protection groups
- Create Interface Profiles and Policy Groups
- Create Switch Profiles
- Understanding the output
- Show VLAN brief
- Show VLAN extended
- Show system internal eltmc info VLAN brief (vsh_lc shell)
Session 4 - Fabric Configuration Part 2


Lectures:



- Overview of interface configurations
- Physical and VMM domains overview
- Deployment immediacy (VMM)
- Resolution immediacy (VMM)
- VLAN Pools
- Static and Dynamic Pools
- Base encap value
- AEPs
- Used as a way to tie VLANs to an Interface
- Used to define EPG membership Policy Groups, Interface Profiles
- Overview of switch configurations
- VPC in ACI
- Switch Profiles
- VLANs in the ACI world
- P I, HW, Access Encap, BD and FD
- Physical Domain, AEP and VLAN Pool relationship to FD_VLAN and VXLAN encap
Labs:



- Create a physical Domain to connect endpoints to the ACI Fabric
- Create VLAN Pool and AEP
- Create a VMM domain to connect endpoints to the ACI fabric
- Create VLAN Pool and AEP
- Create VMM integration
- Create VPCs explicit protection groups
- Create Interface Profiles and Policy Groups
- Create SwitchProfiles
- Understanding the output
- Show VLAN brief
- Show VLAN extended
- Show system internal eltmc info VLAN brief (vsh_lc shell)
Session 5 - ACI Logical Constructs Part 1


Lecture:



- Tenants
- VRFs
- Bridge Domains
- Application Profiles
- EPGs and Endpoint Security Groups
- VMM and Physical Domains
- Intro to Contracts
Labs:



- Create a tenant
- Create an Application Profile
- Create a set of EPGs and establish L2 and L3 connectivity between endpoints
- Create required BDs, EPGs and Contracts
Session 6 - ACI Logical Constructs Part 2


Lecture:



- Tenants
- VRFs
- Bridge Domains
- Application Profiles
- EPGs and Endpoint Security Groups
- VMM and Physical Domains
- Intro to Contracts
Labs:



- Create a tenant
- Create an Application Profile
- Create a set of EPGs and establish L2 and L3 connectivity between endpoints
- Create required BDs, EPGs and Contracts
Session 7 - Contracts


Lecture:



- Contract Scope
- Subjects
- Filters
- Directives (Log and Policy Compression)
- Verifying L2 and L3 permit and denies from the GUI Subject Labels
- Apply both ways and reverse filter ports
- EPG Labels Deny
- Contracts
- Taboo Contracts
- Regular contracts with Deny Filter
- VRF Enforced and Unenforced
- Preferred Group
- VZ_ANY
- Consumed contract interfaces (Intro to leaking)
Labs:



- Enable EPG to EPG communication using Subject Labels and EPG Labels
- Enable EPG to EPG communication using Preferred Group and VZ_Any VRF options
- Block specific traffic using Taboo contracts and deny filters
Session 8 - External Connectivity Part 1


Lecture:



- Layer 2 Connectivity
- Understanding L2Outs
- Understanding VLANs on ACI
- Understanding EPG extensions
- Unicast Routing option on Bridge Domain for migration
- Dual homing Layer 2 connectivity
- Layer 3 Connectivity
- L3Out Building Blocks
- Single L3Outs with Multiple Node Profiles vs Multiple L3Outs with single Node Profile
- Traffic Shaping and traffic flow
- Layer 3 VPC
- Special configuration for HA L4-L7 Devices
- Understanding Subnet options for Ext-EPG
- Advertising routes
- Mapping L3Out to Bridge Domain
- Using Route Maps
- Shared L3Outs
- VRF Leaking overview and verification
- Shared L3Out on Common Tenant
- Shared L3Out on different tenants
- Transit Routing
Labs:



- Create a L2Out and consume a GW outside of ACI
- Replicate the config using an EPG extension
- Create a local L3Out
- Create a Shared L3Out
- Advertise routes not owned by ACI
- Configure an L3out to be preferred over other L3Outs
Session 9 - External Connectivity Part 2


Lecture:



- Layer 2 Connectivity
- Understanding L2Outs
- Understanding VLANs on ACI
- Understanding EPG extensions
- Unicast Routing option on Bridge Domain for migration
- Dual homing Layer 2 connectivity
- Layer 3 Connectivity
- L3Out Building Blocks
- Single L3Outs with Multiple Node Profiles vs Multiple L3Outs with single Node Profile
- Traffic Shaping and traffic flow
- Layer 3 VPC
- Special configuration for HA L4-L7 Devices
- Understanding Subnet options for Ext-EPG
- Advertising routes
- Mapping L3Out to Bridge Domain
- Using Route Maps
- Shared L3Outs
- VRF Leaking overview and verification
- Shared L3Out on Common Tenant
- Shared L3Out on different tenants
- Transit Routing
Labs:



- Create a L2Out and consume a GW outside of ACI
- Replicate the config using an EPG extension
- Create a local L3Out
- Create a Shared L3Out
- Advertise routes not owned by ACI
- Configure an L3out to be preferred over other L3Outs
Session 10 - Deployment Models and DevOps


Lecture:



- Naming Convention
- App Centric and Network Centric
- EPG to Bridge Domain to VLAN and Subnet relationship
- Generic VLAN/Subnet to App Driven VLAN/Subnet
- Whitelisting, Blacklisting, and Graylisting
- Benefits and Drawbacks
- Intro to Automation
- Moquery
- API inspector and postman
- Python
- Cobra SDK
Labs:



- Recreating our lab topology thru Python and Postman
Session 11 - Troubleshooting


Lecture:



- Different CLI shells
- Common troubleshooting commands Structure to
- ACI troubleshooting
- Elam and fTriage CLI
- Understanding how to use show zoning rule
- Common faults and mistakes
- L3Out debugging in the ACI world
Labs:



- Use the discussed tools to troubleshoot connectivity issues between endpoints connected to the ACI fabric and end-points connected via L3Out
Session 12 - Multi-Site and Multi-Pod Part 1


Lecture:



- Active/Active, HA, Metro, and DR
- What it means
- How to choose the correct fit based on business requirements
- Multi-pod
- Components
- Requirements
- Fabric forwarding between Pods
- Multi-site
- Components
- Requirements
- Fabric forwarding between sites
- Stretched vs non-stretched
- Understanding Schema
- Intersite L3Outs
- Azure and AWS
Labs:



- Verifying a multi-pod deployment
- Deploying Tenants using MSO
- Configure App Profile and EPGs from MSO
- Create Local and Stretched Bridge Domains
Session 13 - Multi-Site and Multi-Pod Part 2


Lecture:



- Active/Active, HA, Metro, and DR
- What it means
- How to choose the correct fit based on business requirements
- Multi-pod
- Components
- Requirements
- Fabric forwarding between Pods
- Multi-site
- Components
- Requirements
- Fabric forwarding between sites
- Stretched vs non-stretched
- Understanding Schema
- Intersite L3Outs
- Azure and AWS
Labs:



- Verifying a Multi-pod deployment
- Deploying Tenants using MSO
- Configure App Profile and EPGs from MSO
- Create Local and Stretched Bridge Domains
Session 14 - Design and Migration Considerations


Lecture:



- Integrating ACI to legacy environments Migration Steps
- Migration considerations
- FW Considerations
- Where do we place the GWs?
- Designing based on Zones
- To Service Graph or not to Service Graph
- DMZ inside of ACI vs DMZ outside
- Understanding inbound and outbound traffic flow for multi-DC solutions
- Multi-cloud considerations
- LB considerations
- Single or Multi-hop
- GSLB/GTM requirements for multi-DC solutions
Labs:



- Create a DMZ structure inside of ACI connecting to FWs and LBs
- Test Connectivity from the outside world</outline_plain><duration unit="d" days="14">14 days</duration><pricelist><price country="US" currency="USD">6000.00</price><price country="CA" currency="CAD">8280.00</price></pricelist><miles/></course>