03-13-2026 01:28 PM
Hi,
Quick question regarding the APIC Simulator and a production ACI environment.
I would like to deploy the APIC Simulator as a VM in our virtualization cluster, which is connected to a production Cisco ACI fabric.
My understanding is that the simulator runs the whole ACI fabric internally (simulated leafs/spines, TEPs, GIPO, etc.), and that none of this overlay traffic actually leaves the VM. From the production fabric perspective, it should just appear as a normal VM with a management IP.
Before doing this, I just want to confirm:
Is it safe to run the APIC Simulator inside a VM connected to a production ACI fabric?
Does the simulator generate any VXLAN, multicast, or other fabric-related traffic externally that could interfere with the real fabric?
Or is the only external traffic basically regular management traffic (HTTPS/SSH/ICMP) from the VM?
Thank you!
Solved! Go to Solution.
03-25-2026 08:00 AM - edited 03-25-2026 08:00 AM
Hi,
You can run the ACI Simulator VM inside a production ACI fabric safely.
Treat it like a normal workload in its dedicated EPG for example.
All of the ACI stuff stays within the VM. There will be no VXLAN to real leaves,
no TEP adjacency, no IS-IS, no multicast flooding etc.
There will be only HTTPS/SSH/ICMP etc, as you mentioned.
"Some of the simulated switch ports have been mapped to the front-panel server ports,
which allows you to connect external management entities such as ESX servers, vCenters,
vShields, bare metal servers, Layer 4 to Layer 7 services, AAA systems, and other physical
or virtual service VMs." - https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/release-notes/cisco-aci-simulator-release-notes-621.html
I hope this helps.
03-25-2026 08:00 AM - edited 03-25-2026 08:00 AM
Hi,
You can run the ACI Simulator VM inside a production ACI fabric safely.
Treat it like a normal workload in its dedicated EPG for example.
All of the ACI stuff stays within the VM. There will be no VXLAN to real leaves,
no TEP adjacency, no IS-IS, no multicast flooding etc.
There will be only HTTPS/SSH/ICMP etc, as you mentioned.
"Some of the simulated switch ports have been mapped to the front-panel server ports,
which allows you to connect external management entities such as ESX servers, vCenters,
vShields, bare metal servers, Layer 4 to Layer 7 services, AAA systems, and other physical
or virtual service VMs." - https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/release-notes/cisco-aci-simulator-release-notes-621.html
I hope this helps.
03-25-2026 12:05 PM
Thank you, it helps me a lot!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide