Cisco ACI Flashcards

1
Q

What are Endpoints?

A

physical or virtual devices, such as servers, virtual machines, or containers, that communicate over a network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is an Endpoint Group (EPG)?

A

a logical grouping of endpoints that require similar policy settings, such as security, quality of service (QoS), and Layer 4 to Layer 7 services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a Consumer EPG?

A

group of endpoints that initiate the communication or consume a service provided by another EPG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Provider EPG?

A

group of endpoints that offer services or respond to the requests initiated by consumer EPGs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Contract?

A

policy that defines the rules and conditions for communication between Endpoint Groups (EPGs)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Bridge Domain (BD)?

A

fundamental construct that acts as a Layer 2 broadcast domain within the fabric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is L3Out?

A

configuration construct that enables the ACI fabric to connect to external networks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is vzAny?

A

allows administrators to apply policies across multiple Endpoint Groups (EPGs) without the need to explicitly configure each EPG individually

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is Application Policy Infrastructure Controller (APIC)?

A

centralized management and control software for the ACI fabric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are L4-L7 Services?

A

insert services like firewalls, load balancers, and intrusion prevention systems (IPS) between EPGs to enhance security and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the role of the Cisco ACI plugin?

A

insert a firewall between EPGs as a Layer 4 to Layer 7 service

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What types of traffic can a PA FW secure in Cisco ACI?

A
  • east-west traffic between the application tiers within EPGs
  • north-south traffic between users and the applications
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

All the entities in the ACI Fabric are connected to which switches?

A

leaf switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

To what swtiches are leaf switches connected to?

A

larger spine switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What does a network administrator need to do to secure the traffic between the application tiers?

A

insert the PA FWs as L4 to L7 services between each EPG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does a network administrator need to create to define what services the L4 to L7 device provide?

A

service graph

17
Q

When the firewall is integrated with Cisco ACI, what is used to send trafic to the firewall?

A

Policy-Based Redirect (PBR)

18
Q

How are firewalls deployed in Cisco ACI?

A

through Service Graphs

19
Q

Do the integrated L4-L7 devices need to be configured as default gateway to be able to inspect the traffic?

A

no, a service graph allows to integrate Layer 4 - Layer 7 devices, such as a firewall, into the flow of traffic without the need for the L4-L7 device to be the default gateway for the servers in the ACI fabric

20
Q

How is the VM firewall configured in the APIC?

A

as a device cluster

21
Q

How are the PA VM firewalls represented in the ACI fabric?

A

L4-L7 device

22
Q

What does it mean that Cisco ACI integration supports physical firewalls divided into contexts that are managed by ACI as individual firewalls?

A

that vsys is supported in ACI

23
Q

What needs to be configured when deploying a multi-vsys firewall in ACI?

A

a chassis manager in the tenant, which is assigned to the firewall service

24
Q

What defines the logical interfaces that are assigned to the consumer and provider EPGs?

A

the service graph template

25
Q

After creating a service graph template, what does it need to be assigned to?

A

EPGs and contracts