Vendor Platform Study · Cisco lane · Rack elevation view

Cisco Data Center
Every plane, one cabinet.

The whole portfolio laid out the way it is actually racked: control towers on top, telemetry and security in the middle, compute / fabric / SAN as the payload, AI rigs at the bottom. Hover or tap any module to trace what it talks to.

control / API data, fabric & SAN security enforcement telemetry / observability AI infrastructure legacy / end of sale
42
Operators & IaC
Terraform · Ansible · NACGitOps front door
NSOservice orchestration
CMLlab / simulation
41
Control towers
IntersightIMM · ICO · advisories
Nexus Dashboardfabric ops platform
Hyperfabriccloud-managed fabric
Cloud Network CtrlACI → public cloud
40
ND services
NDFCfabric + SAN controller
NDIinsights & assurance
NDOmulti-site orchestration
Data Brokerpacket broker
APICACI policy controller
39
Observability
SplunkSIEM + data platform
AppDynamicsAPM
ThousandEyespath visibility
SAN Analyticsper-IO telemetry
38
Security
Secure Workloadmicrosegmentation
HypershieldeBPF / DPU enforcement
Secure FirewallFTD · FMC · DDoS
ISEAAA · TrustSec
Isovalent CiliumK8s eBPF security
MACseclink encryption
37
LAN fabric
Nexus 9000NX-OS / ACI leaf-spine
Border GW / DCImulti-site
Nexus 3000low-latency ToR
Nexus 7K · 5K · FEXend of sale
36
Compute
Fabric InterconnectsFI-A / FI-B · IMM
UCS X · B · C · Sstateless servers
CIMCBMC / Redfish
UCSM · Central · HXlegacy
HCI w/ NutanixHyperFlex successor
vSphere · OpenShiftplatform layer
35
SAN fabric
MDS 9000FC / NVMe-oF directors
Arrays (CVD partners)Pure · NetApp · Hitachi
NVMe/TCP on NexusIP storage path
34
AI infrastructure
C885A · X440p GPUGPU servers
800G AI fabricRoCEv2 · DLB
AI PODs · AI Factoryvalidated designs
AI Defensemodel guardrails
33
Trust core
Smart LicensingSSM On-Prem
NTP · DNS · PKItrust core
OOB mgmtconsole · mgmt0
Hover a module
Cables light up to show what it depends on and what it feeds. Tap on mobile.

One switch, two personalities

Nexus 9000 boots as a classic NX-OS switch or as an ACI leaf/spine. Pick per fabric, before purchase — conversion wipes the box.

NX-OS mode (+ NDFC)ACI mode (+ APIC)
Control planeDistributed — BGP/OSPF/IS-IS + VXLAN EVPN on every switchCentralised — APIC pushes policy; switches run a thin image
Configuration modelCLI/NETCONF/gNMI per device; NDFC for fabric intentObject model (tenant/VRF/BD/EPG/contract); no switch CLI config
SegmentationVLAN/VRF/VNI + ACLs; TrustSec optionalContracts = default-deny allow-list (zero trust by construction)
Multi-siteVXLAN Multi-Site with Border Gateways via NDFC/NDOMulti-Pod / Multi-Site via NDO; Remote Leaf; Cloud Network Controller
VirtualisationNDFC vCenter plugin onlyVMM domains: vCenter, Hyper-V, OpenStack, K8s/OpenShift, AHV
LabNexus 9300v/9500v (full control plane)ACI Simulator (policy/API only, no data plane)
Best fitOpen standards, mixed vendors, traditional net-opsMulti-tenant, regulated, policy-driven, multi-site

How a workload gets built

The same request touches every plane. Order matters — identity and fabric before storage, storage before security, security before go-live.

Intent in GitTerraform / NAC plan opened as a PR; NDI pre-change assurance runs in CI.
Server ProfileIntersight pulls MAC/WWN/UUID from pools, applies BIOS/boot/firmware, FI programs the VIC.
Fabric policyNDFC or APIC creates VRF, network/BD, EPG/ESG, contracts; leaves get VNI, anycast GW, L3Out.
SAN zoningNDFC SAN zones host WWPN ↔ array in its VSAN; LUN via Pure/NetApp plugin; boot-from-SAN.
EnforcementSecure Workload scope + discovered policy enforced on host; FTD via ePBR/service graph.
BaselinegNMI → NDI → Splunk; ThousandEyes test; AppD agent; post-change anomaly check closes the ticket.
East-west packet walk (VXLAN EVPN + microsegmentation)
 VM-A (Leaf1, VNI 30010) ─► Secure Workload host policy permits tcp/443
   ─► Leaf1 EVPN type-2 lookup for VM-B ─► VXLAN encap (anycast GW, symmetric IRB)
   ─► ECMP Spine1/Spine2 (IS-IS/OSPF underlay · BGP EVPN overlay)
   ─► Leaf3 decap ─► (optional) ePBR ─► FTD cluster ─► VM-B
 Telemetry: flow record → NDI · host flow → Secure Workload · both → Splunk

HA rules that hold up in audits

Controllers

  • APIC 3 nodes (5/7 at scale), ND 3 app + data nodes, Intersight PVA 3 nodes, FMC HA pair, ISE 2+ PSNs
  • Spread across racks and A/B power; nightly encrypted config exports; quarterly restore drill

Fabric

  • Spines N+1 with ECMP; leaves in vPC pairs (fabric peering); hosts dual-homed
  • Two Border Gateways per site, diverse circuits, MACsec on DCI; never stretch vPC between sites
  • ISSU / GIR one leaf at a time; BFD everywhere

Compute & SAN

  • FI-A/FI-B always; dual VIC; vNIC failover at the VIC not the OS
  • Two physically separate FC fabrics; dual HBAs; MPIO; single-initiator smart zoning

Security & services

  • FTD cluster on spanned EtherChannel via vPC; PBR health checks; symmetric hashing
  • Two NTP, two DNS, two ISE; local fallback accounts vaulted (CyberArk)

Lab build-outs by zone

Every tier keeps the same three zones. Controllers and data plane live in trust; only the bastion, firewall, proxy and probes sit in the DMZ; untrust is the outside world.

untrust

lab-edge-fw (VyOS/ASAv)

dmz

lab-jump (RHEL bastion + nginx)

trust

n9kv-spine1n9kv-leaf1ucspeapic-sim OR nd-ndfc
≈30 vCPU / 90 GB. VXLAN EVPN CLI, UCSM profiles, one controller. Intersight SaaS trial from the jump host.

Compliance map

DoD baseline first, then the Vanta 38-framework catalog reuses the same 800-53 control evidence. Everything exports to Splunk + Git, so one evidence pipeline serves every framework.

DISA STIG / SRGNX-OS L2S/RTR/NDM, ASA/FTD/FMC, ISE, RHEL/ESXi; ND/Intersight/SW → App Server SRG
DoDIN APL · NIAP CCNexus, MDS, UCS, ISE, Secure Firewall listed; run NDcPP/FWcPP evaluated configs
FIPS 140-2/3FIPS mode on NX-OS, APIC, FI, FTD, ISE, ND, PVA at install (wipes config)
CNSA 1.0 → 2.0AES-256-GCM MACsec XPN, P-384/RSA-3072+, SHA-384; track ML-KEM/ML-DSA + LMS firmware signing
NIST 800-53 r5 · 800-207SC-7 zones/contracts, SC-8 MACsec/TLS, IA-2 CAC via ISE, AU via Splunk, SI-4 NDI/SW; ACI/SW/Hypershield = PEPs
DoD ZT overlays · 800-171 · CMMCNetwork & Environment pillar = ACI/NDFC SDN; Device = Intersight; Visibility = NDI/Splunk
SOC 2 · ISO 27001/17/18/701Config exports, IaC history, NDI pre-change as change-mgmt evidence
FedRAMP · CJIS · HIPAA/HITRUSTCheck Cisco SaaS (Intersight, Nexus Cloud, TE, Splunk) authorizations; tenant/VRF isolation for PHI/CJI
PCI DSS 4.0 · GDPR · CCPAACI contracts shrink PCI scope; EU-site VRFs for residency
DORA · NIS 2 · ISO 22301Multi-Site HA, DR drills, Cisco as critical ICT third party
ISO 42001 · EU AI ActAI PODs lifecycle, AI Defense guardrails, Hypershield audit trails
Essential Eight · Cyber Essentials · sector variantsSTIG baseline exceeds; reuse the 800-53 crosswalk (TISAX, TX-RAMP, StateRAMP, NY DFS, FFIEC, SOX, GLBA, FERPA, SOC 1, SSPA, CSA STAR, ISO 9001, Custom)