cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1443
Views
10
Helpful
4
Replies

ACI Operational Modes

visitor68
Level 4
Level 4

Folks, hope everyone is doing well. It's been a while since I approached this issue and a long while since I had any interaction with ACI. Please remind me of the different modes that ACI can run in...

I think one is "Application Mode" or "Application Centric" mode, which is what you use if you really have a deep understanding of the applications and their requirements. In that sense, you can use the ACI constructs, like EPGs and BDs and tenants in the way ACI was meant to be leverage them. 

I believe there is also a more legacy way of doing things, where I think they call it "Network-Centric" mode. Basically, meaning you are using VLANs, mapped 1:1 to subnets and you do all the things basically the old fashioned way on an ACI fabric.

Is this correct?

1 Accepted Solution

Accepted Solutions

Yes and Yes
We have many customers running NSX on ACI, though IMHO I think its overkill.  You can accomplish everything with native ACI, it just comes down to which technology a customer wants to implement the Policies with.  
You can also create a standalone fabric using DCNM like you said, which would automate the underlay provisioning for a fabric of N9K NXOS switches.  

https://www.cisco.com/c/en/us/products/collateral/switches/nexus-9000-series-switches/white-paper-c11-740124.html

https://blogs.vmware.com/networkvirtualization/2018/09/reference-guide-update-nsx-on-aci.html/
Robert

View solution in original post

4 Replies 4

Robert Burns
Cisco Employee
Cisco Employee

There's no operational "mode" per-say, its just a way to organize your ACI policies.  Network centric follows a more legacy design where EPG = BD = VLAN, and there's less emphasis on Segmentation.  App centric design requires having working knowledge of application dependencies, so you can implement security policies to allow the only required communications between endpoints and thus provides a more secure deployment.  

Robert

Thanks, Robert. 

And last question...there's no such thing as using ACI as an intelligent underlay without using any ACI constructs, right? I'm asking this because IHAC who is using NSX, but they want an automated underlay. Or at least an underlay that can be managed holistically as a fabric. IMHO, ACI is a lot of money to pay for that. And the ACI constructs, along with the added encapsulation at the leaf, seems to be a bunch of added complexity with relatively little benefit. 

Does Cisco have an NXOS-based solution that has a central management engine (like DCNM) that can deploy and manage a routed underlay easily?

Yes and Yes
We have many customers running NSX on ACI, though IMHO I think its overkill.  You can accomplish everything with native ACI, it just comes down to which technology a customer wants to implement the Policies with.  
You can also create a standalone fabric using DCNM like you said, which would automate the underlay provisioning for a fabric of N9K NXOS switches.  

https://www.cisco.com/c/en/us/products/collateral/switches/nexus-9000-series-switches/white-paper-c11-740124.html

https://blogs.vmware.com/networkvirtualization/2018/09/reference-guide-update-nsx-on-aci.html/
Robert

Thank you

Save 25% on Day-2 Operations Add-On License