ACI as the foundation of the software define datacenter
September 10, 2020
ACI as the foundation of the software define datacenter

Score 8 out of 10
Vetted Review
Verified User
Overall Satisfaction with Cisco Application Centric Infrastructure (Cisco ACI)
We use ACI in our new SDDC (Software Defined Data Center) which is used in three different data center locations in Europe to be able to deliver a hybrid cloud to our internal customers worldwide. This is a network area that is deployed in parallel to our existing legacy network.
Pros
- Automated deployment of the network
- Microsegmentation inside of VLANs
- Better monitoring options
Cons
- No redundancy in the deployment (if an error is deployed it's everywhere at the same time)
- Complete change of mind of the network operations team needed
- Very complex deployment if done manually (needs automation)
- There was a high initial investment in the hardware.
- Due to the automated and standardized configuration, we are much faster in deploying changes. Even possible as self-service for the customer.
- We have fewer problems caused by human errors due to the automated configuration approach.
We integrated the Cisco Firepower Firewall in the SDDC. The firewall and the ACI controller exchange the EPG information. The EPGs are then configuration objects on the firewall and are always up to date.
We integrated ACI with Splunk which gives users a much better monitoring experience then we have with SNMP traps with the legacy network.
We integrated ACI with Splunk which gives users a much better monitoring experience then we have with SNMP traps with the legacy network.
An alternative to ACI would be to use VMware NSX-T. The advantage of NSX-T is that the micro-segmentation is implemented with a distributed firewall and not with ACL. The disadvantages are that you would still need an additional pyhsical network as underlay that has to be managed independent of the overlay and that you can only integrate virtualised systems that are supported from the product and bare metal workload that has additional software installed to support NSX-T.
With ACI underlay and overlay are configured with the same REST API and all devices can be integrated.
With ACI underlay and overlay are configured with the same REST API and all devices can be integrated.
Comments
Please log in to join the conversation