The choice between Multi-Pod and Multi-Site is not about latency or distance. It is about how big you want your change domain to be. Everything else follows.
The choice between Multi-Pod and Multi-Site is not about latency or distance. It is about how big you want your change domain to be. Everything else follows.
VRF leaking in ACI used to be configured by accident, through contracts and subnet flags. ESGs separate leaking from filtering, and that changes the design.
Three defaults in ACI will drop your traffic without telling you: subnet scope flags, external EPG scoping across the VRF, and the OSPF route tag in a transit design.
The L3Out is where ACI stops being novel and starts being VRF-lite on a leaf switch. Border leaf design, interface types, floating L3Out and convergence.
Tenants, VRFs, bridge domains, EPGs and contracts are the easy part. The access policy chain is configured in a separate tree, and that is what catches people.
Most ACI explanations start with the policy model, which is backwards. Start with the three planes and the fact that the APIC is not in the data path.