Cisco ACI EPGs & Contracts
ACI's policy model (tenants, bridge domains, EPGs, contracts) is hard to internalize without a real fabric to click through. This lab gives you a live APIC managing an actual spine/leaf fabric, so policy changes show up as real traffic behavior, not diagram theory.
The problem
Two EPGs have a contract between them and traffic flows in one direction, but replies never make it back, as if the fabric is silently dropping half the conversation.
What you'll practice
- Create tenants, VRFs and bridge domains in APIC
- Build EPGs and map them to physical/virtual domains
- Write contracts and filters to control EPG-to-EPG traffic
- Verify policy enforcement with real inter-EPG traffic tests
- Read fault and health-score data from the APIC dashboard
The topology
An APIC controller manages a two-leaf, one-spine ACI fabric with endpoints attached to each leaf, the minimum real spine/leaf topology needed to see EPG and contract behavior actually enforced.
Topology diagram
Frequently asked
Do I need my own APIC license or spine/leaf hardware?
No. The APIC controller and fabric are already licensed and running. You build tenant policy, not infrastructure.
Is this relevant to CCNP Data Center (DCACI)?
Yes. Tenants, bridge domains, EPGs and contracts are core DCACI blueprint topics, covered hands-on in this lab.
Ready to run this lab yourself?
No setup, no image sourcing. Book a session or ask for a live demo.