top of page

Search
PBR Concepts
What is a Health Group? A Health Group is a configuration object used to group specific PBR destination interfaces—typically the consumer and provider interfaces of the same service node (such as a firewall or load balancer)—into a single logical unit for health tracking. How is it Useful? The primary purpose of a Health Group is to prevent traffic black-holing when a service node experiences a partial failure. 1. Prevents Traffic Black-Holing In a typical PBR deployment,
Mukesh Chanderia
Feb 1622 min read
Active/Standby F5 Across Different ACI Pods
Normal L3Out vs Floating L3Out Explained Understanding Cisco ACI Multi-Pod Architecture In a Cisco ACI Multi-Pod design: Each Pod has an independent IS-IS control plane Endpoint learning is maintained through COOP Inter-pod communication uses MP-BGP Pods are interconnected via the IPN (Inter-Pod Network) Each Pod effectively behaves like an independent availability zone . When deploying: Active F5 in Pod 1 Standby F5 in Pod 2 You achieve true failure domain isolation, signifi
Mukesh Chanderia
Feb 114 min read
Multi-site Traffic Flow
This article explains how traffic flows between Endpoint Groups (EPGs) across multiple sites in Cisco ACI using Nexus Dashboard Orchestrator (NDO). We will walk through three common design scenarios and explain both the configuration steps and the underlying traffic behavior. 1. Stretched Bridge Domain with Site-Local EPGs (Layer 2 Inter-Site Traffic) Scenario Overview In this scenario: EPG1 is located in Site 1 EPG2 is located in Site 2 Both EPGs belong to the same Bridge
Mukesh Chanderia
Feb 97 min read
In-Band Management Configuration in ACI
High-Level Objective The goal is to enable APICs, leaf switches, and spine switches to: Use in-band management IP addresses Carry management traffic over the ACI fabric data plane Reach external management services such as DNS, NTP, TACACS, Syslog, and monitoring systems To achieve this, Cisco ACI requires three mandatory building blocks , exactly as defined in the official documentation: Access policies to carry the In-Band VLAN In-Band management IP addressing within
Mukesh Chanderia
Jan 44 min read
bottom of page