The choice between Multi-Pod and Multi-Site is not about latency or distance. It is about how big you want your change domain to be. Everything else follows.
The choice between Multi-Pod and Multi-Site is not about latency or distance. It is about how big you want your change domain to be. Everything else follows.
VRF leaking in ACI used to be configured by accident, through contracts and subnet flags. ESGs separate leaking from filtering, and that changes the design.
The L3Out is where ACI stops being novel and starts being VRF-lite on a leaf switch. Border leaf design, interface types, floating L3Out and convergence.
Three defaults in ACI will drop your traffic without telling you: subnet scope flags, external EPG scoping across the VRF, and the OSPF route tag in a transit design.
Tenants, VRFs, bridge domains, EPGs and contracts are the easy part. The access policy chain is configured in a separate tree, and that is what catches people.
Most ACI explanations start with the policy model, which is backwards. Start with the three planes and the fact that the APIC is not in the data path.
Cisco Cloud Control promises one login, one inventory and correlated alerts across the Cisco estate. What’s real, what’s roadmap, and what I’d flag.
Use Claude Code with the OPNsense API to document your firewall in Git and make changes in plain English, staged then applied behind two approval gates.
Use Claude Code with the UniFi Network API to document your network in Git and make device changes in plain English, gated on approval before anything is sent.