cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1531
Views
0
Helpful
6
Replies

Cloud ACI in AWS

SIMMN
Spotlight
Spotlight

I have a customer who runs Cisco SD-WAN cloud onramp with AWS already and they are looking to extend ACI into AWS as well. I still do not understand why the SD-WAN can not be used for ACI multi-site inter-site transport between On-prem and AWS...But it is not what I am asking here...

 

When setting up the SD-WAN cloud onramp, there was a transit VPC created to host the sd-wan edge virtual instances. To instantiate Cloud APIC in AWS, the Infra VPC would be created. So my question is can I re-use the existing transit VPC as the infra VPC for Cloud ACI?

1 Accepted Solution

Accepted Solutions

Huyen Duong
Cisco Employee
Cisco Employee

Hi,

As of today, you cannot re-use existing transit VPC for Cloud APIC deployment. Cloud APIC deployment process from AWS marketplace will bring up new Infra VPC.

Thanks

View solution in original post

6 Replies 6

Huyen Duong
Cisco Employee
Cisco Employee

Hi,

As of today, you cannot re-use existing transit VPC for Cloud APIC deployment. Cloud APIC deployment process from AWS marketplace will bring up new Infra VPC.

Thanks

Okey, so I would have to do a VPC peering between Transit VPC and Infra VPC if I need the workloads in the two to communicate, right?

Hi, 

Not VPC Peering, as cAPIC will not do VPC peering with un-managed VPC. Pls see this link for reference

https://www.cisco.com/c/en/us/td/docs/dcn/aci/cloud-apic/use-case/configuring-external-connectivity-using-nexus-dashboard-orchestrator/m-configuring-external-connectivity-overview.html

 

In brief, from cAPIC we can create external connectivity using IPSec and BGP to SDWAN edge. Then 2 domains SDWAN and Cloud ACI can talk to each other.

 

Thanks !

Thanks for the link! So from a quick glance, it would be just typical ipsec tunnels between Infra and Transit VPCs, just like between Infra and User VPCs, right?

Hi
Yes, to be correct it is IPSec between CSR(now is Catalyst 8000V) managed by Cloud APIC and cEdge managed by vManage.

This solution is used to connect Cloud ACI solution to any non-ACI network.

Thanks!

Review Cisco Networking for a $25 gift card

Save 25% on Day-2 Operations Add-On License