Sunday, 31 August 2025

Cisco ACI Port Security – MAC Limit, Protect Mode & APIC Configuration Guide

 

Cisco ACI Port Security – MAC Limit, Protect Mode & APIC Configuration Guide

Cisco ACI Port Security is a critical feature for securing access layer ports in your ACI fabric. It controls the number of MAC addresses that can be learned on an interface, protecting against MAC flooding attacks and unauthorized device access.

In this guide, we cover everything you need to know — how it works, its restrictions, configuration steps in APIC, and how to monitor violations.

🔐 What is Cisco ACI Port Security?

Port Security in Cisco ACI limits the number of MAC addresses allowed to be learned on a given interface. When the limit is exceeded, ACI takes a Protect action — dropping traffic from unknown MAC addresses and temporarily halting MAC learning on that port.

This is especially useful in environments where you want to prevent rogue devices from flooding the ACI fabric's endpoint table (COOP database).

⚙️ Key Features of ACI Port Security

  • MAC Limit: Set a maximum of 0 to 12,000 MAC addresses per interface.
  • Protect Mode: The only supported violation action. Excess MACs are dropped silently.
  • Learning Timeout: MAC learning is disabled temporarily (default: 60 seconds) when the limit is breached, then resumes automatically.
  • Supported Interfaces: Physical ports, Port Channels, and vPCs.
  • Monitoring: ACI generates faults and syslogs when the MAC limit is exceeded.

🚫 Restrictions & Limitations

  • Port Security is not supported on FEX (Fabric Extender) ports.
  • Only MAC address limits are enforced — MAC+IP sticky binding is not supported in ACI.
  • You cannot configure "Shutdown" or "Restrict" violation modes (unlike classic NX-OS port security).

🛠️ Configuration Steps in APIC GUI

Follow these steps to configure Port Security in Cisco ACI via the APIC GUI:

  1. Navigate to Fabric → Access Policies → Interface Policies → Port Security
  2. Click + to create a new Port Security Policy
  3. Set the Maximum Endpoints (MAC limit) — e.g., 5 for an access port
  4. Set the Violation Action to Protect
  5. Set the Timeout value (default 60 seconds)
  6. Attach this policy to an Interface Policy Group (Leaf Access Port or vPC Policy Group)
  7. Bind the Policy Group to your Interface Profile under the correct Switch Profile

📊 How Protect Mode Works — Step by Step

  1. ACI learns MAC addresses on the port normally until the configured limit is hit.
  2. Once the limit is reached, any new (unknown) source MAC is dropped at the leaf.
  3. MAC learning is paused on that interface for the timeout duration.
  4. After the timeout expires, learning resumes — if original MACs age out, new ones can be learned.
  5. A fault is raised in APIC and a syslog is generated for visibility.

🔍 Monitoring Port Security Violations

You can monitor Port Security violations from:

  • APIC GUI → Fabric → Inventory → Leaf → Faults
  • Operations → Faults (filter by "port-security")
  • Syslog forwarding to your external syslog server

💡 Interview Questions — Cisco ACI Port Security

If you are preparing for CCNP DC or CCIE Data Center interviews, here are common questions on this topic:

  1. What violation modes are supported in ACI Port Security?
  2. Can you configure Port Security on FEX ports?
  3. What happens when a MAC limit is exceeded in Protect mode?
  4. How long does the learning timeout last by default?
  5. Where do you attach the Port Security policy in ACI?
  6. What is the maximum MAC address limit you can set per interface in ACI?
  7. How does ACI Port Security differ from NX-OS Port Security?

📚 Related Posts You May Also Like

Found this helpful? Leave a comment below or share it with your network. For Cisco ACI / Nexus consulting or freelancing, reach out at rockingoa@gmail.com

Saturday, 30 August 2025

Cisco ACI - Fabric Secure Mode Overview

 Fabric Secure Mode Overview

Fabric Secure Mode is a security feature in Cisco ACI that safeguards the infrastructure from unauthorized additions. It ensures that only verified switches and APIC controllers can join the fabric, even if someone has physical access to the equipment.

Starting from release 1.2(1x), Cisco ACI performs a validation check during installation or upgrade. This check confirms that each device has a valid serial number and a Cisco-signed digital certificate.

By default, the system operates in Permissive Mode, allowing existing setups to continue functioning even if some devices lack valid certificates. However, administrators can enable Strict Mode for enhanced security, requiring manual approval for any new device joining the fabric.


⚙️ Modes of Operation

Mode

Permissive Mode (Default)

Strict Mode

Device Validation

Valid Cisco serial number and certificate required

Enforces serial number and certificate validation

Existing Fabric

Continues operating even with invalid certificates

Requires all devices to be validated

Authorization

Auto-discovers and allows devices without manual approval

Manual authorization needed for each new device

Security Level

Basic security

Enhanced security and control


To change the Fabric Secure Mode in Cisco ACI (e.g., from Permissive to Strict), follow these steps using the Cisco APIC GUI:

🔧 Steps to Change Fabric Secure Mode

  1. Log in to the APIC GUI.
  2. Navigate to:
    System → System Settings → Fabric Security
  3. In the Properties pane, locate the Fabric Secure Mode setting.
  4. Select Strict Mode from the available options.
  5. Save the configuration.
  6. Reboot the APIC and affected switches to apply the change.

⚠️ Important: Changing the mode requires a reboot for the configuration to take effect.

Cisco ACI - Node Stateful Vs Stateless reload

 

Aspect

Stateful Reload

Stateless Reload

Definition

Reload where process state is preserved using checkpoints

Reload where process starts fresh without any prior state

State Preservation

Yes – runtime state is saved to Persistent Storage Services (PSS)

No – process is restarted without retaining previous state

Recovery Speed

Faster – resumes from last known state

Slower – requires full reinitialization

System Impact

Minimal – seamless continuation of operations

Higher – may cause temporary disruption or delay

Use Case

Preferred for critical services needing quick recovery

Used when state cannot be preserved or process needs a clean start

Managed By

Persistent Storage Services (PSS)

System Manager

Example Scenario

Restarting a service with session data intact

Replacing a crashed process with a new instance

 

Thursday, 28 August 2025

ACI Node state - undiscovered Vs Unknown

 

  Undiscovered:

  • You’ve manually added a node ID in APIC.
  • The switch is not yet connected or powered on.
  • Could be due to cabling issues or incorrect port configuration.

  Unknown:

  • The switch is physically connected and sending LLDP packets.
  • APIC detects it but doesn’t have a matching Node ID policy.
  • You need to assign a Node ID to complete discovery.

 

Tuesday, 26 August 2025

What is a Contract Preferred Group in ACI?

 🔷 What is a Contract Preferred Group in ACI?

In Cisco ACI, Endpoint Groups (EPGs) typically require contracts to communicate with each other. This follows the “allow list” model, where communication is explicitly permitted only if a contract exists.

The Preferred Group (PG) feature simplifies this by allowing certain EPGs within the same VRF to communicate freely without contracts.


Key Concepts

Term

Description

Included EPGs

EPGs that are part of the preferred group and can communicate with each other without contracts.

Excluded EPGs

EPGs outside the preferred group that still require contracts to communicate.

VRF PG Setting

Must be enabled for the preferred group to work. Without this, even included EPGs won’t communicate freely.


🛠️ Configuration Steps

  1. Enable Preferred Group on VRF:
    • Go to the VRF settings in APIC or Nexus Dashboard Orchestrator (NDO).
    • Check the Preferred Group box.
  2. Add EPGs to the Preferred Group:
    • In the EPG properties, check Include in Preferred Group.
    • Save the configuration.
  3. Verify Membership:
    • You can view all EPGs in the preferred group under the VRF’s properties.

🌐 Multi-Site Considerations

  • In a stretched VRF across multiple sites, preferred group EPGs are shadowed in other sites to enable inter-site communication.
  • This allows, for example, a web EPG in Site 1 to communicate with an app EPG in Site 2 without contracts.

⚠️ Limitations

  • Preferred Groups are not supported for L3Out external EPGs.
  • If vzAny is already consuming/providing a contract in the VRF, you should not configure preferred groups.
  • All EPGs in a preferred group must be managed consistently (either all via APIC or all via NDO).

 

ACI Leaf Switch Replacement

 To replace a Cisco ACI leaf switch, follow these step-by-step instructions to ensure a smooth transition without disrupting your fabric:


🛠️ Preparation

  1. Document the existing switch details:
    • POD ID
    • Node ID
    • Node Name
    • Serial Number 
  1. Ensure the replacement switch is in ACI mode:
    • Connect via console and run show version.
    • If in NX-OS mode, convert to ACI mode using Cisco's documented procedure 
    • Before adding the new leaf switch to the fabric, ensure it's manually upgraded to the target image or one with a direct upgrade path. Avoid using intermediate images that require multiple upgrade steps, as they can trigger issues and impact your production environment. A final upgrade via policy helps ensure BIOS and FPGA components are properly updated.
  1. Clean up the replacement switch:
    • Run setup-clean-config.sh and then reload to remove any existing configuration 

🔄 Decommission the Faulty Leaf Switch

  1. Go to APIC GUI:
    Fabric > Inventory > Fabric Membership
  2. Right-click the faulty switch → Select Decommission.
  3. Once decommissioned, Remove from Controller and confirm the action 
  4. Physically disconnect and unmount the old switch.

🔌 Install and Connect the New Leaf Switch

  1. Mount the new switch and connect uplinks to spine switches. DONOT CONNECT DOWNLINK AT THIS STAGE
  2. Power on the switch.
  3. In APIC GUI, go to:
    Fabric > Inventory > Fabric Membership > Nodes Pending Registration
  4. Verify serial number, then Register the switch:
    • Use the same POD ID, Node ID, and Node Name as the old switch 
  1. Once registered, go to:
    Fabric > Inventory > Fabric Membership > Registered Nodes
    → Right-click → Select Commission.
  2. Wait for the switch to reach Active state.

🔍 Post-Replacement Validation

  1. Connect downlink cables (after switch is active).
  2. Go to:
    Fabric > Inventory > Topology
    → Verify the switch is visible and operational.
  3. SSH into APIC and run:

→ Confirm switch status is active 

  1. If you get SSH warnings (e.g., DNS spoofing), update the known_hosts file:

🧩 Troubleshooting Tips

  • Switch not discovered: Check LLDP neighbors and cable connections.
  • Switch shows "Not Supported": Upgrade APIC firmware to match switch model.
  • No TEP IP assigned: May be a DHCP issue—contact Cisco TAC.
  • SSL issues: Check for established sessions on port 12215 

Sunday, 24 August 2025

Common Causes of "Unknown" Leaf State

 

 Common Causes of "Unknown" Leaf State

  • Certificate Issues: The leaf might not be presenting a valid certificate chain to the APIC, which prevents proper SSL handshake and authentication.

  • LLDP Mismatch or Failure: ACI relies on LLDP (Link Layer Discovery Protocol) for fabric discovery. If LLDP info isn’t exchanged correctly between APIC and leaf, discovery fails.

  • Firmware Incompatibility: The leaf switch might be running a version of ACI software that’s not compatible with the APIC or spine switches.

  • Hardware Problems: Faulty transceivers, cables, or ports can block communication between APIC and leaf.

  • Time Sync Issues: If the leaf’s system time is out of sync with the APIC, certificate validation may fail.

  • Incorrect Node ID or Serial Number: If the leaf was previously part of another fabric or misconfigured, it may need to be wiped and re-initialized.