📝 Section Review: Cisco ACI
اہم نکاتKey TakeawaysKey Takeaways
- ACI controller-driven ہے: APIC policy رکھتا ہے، switches صرف forward کرتے ہیں۔ACI controller-driven hai: APIC policy rakhta hai, switches sirf forward karte hain.ACI is controller-driven: the APIC holds the policy, switches just forward.
- Object chain ہے: endpoint → EPG → bridge domain → VRF → tenant۔Object chain hai: endpoint → EPG → bridge domain → VRF → tenant۔The object chain is endpoint → EPG → bridge domain → VRF → tenant.
- Policy EPGs سے جڑتی ہے، کبھی individual ports سے نہیں۔Policy EPGs se jurti hai, kabhi individual ports se nahi.Policy attaches to EPGs, never to individual ports.
- Contracts ڈیفالٹ deny ہوتے ہیں؛ filters allowed ports/protocols define کرتے ہیں۔Contracts default deny hote hain; filters allowed ports/protocols define karte hain.Contracts are deny-by-default; filters define the allowed ports/protocols.
- Contract کام کرنے کے لیے ایک EPG پر provided اور دوسری پر consumed ہونا چاہیے۔Contract kaam karne ke liye ek EPG par provided aur doosri par consumed hona chahiye.A contract must be provided on one EPG and consumed on the other to work.
خود جانچ (مشق)Self-Check (Practice)Self-Check (Practice)
یہ مشقی سوالات ہیں، امتحانی سوالات نہیں۔These are practice questions, not exam questions.These are practice questions, not exam questions.
❓ EPG کیا ہے اور ACI میں policy کہاں رہتی ہے؟ (Practice سوال)EPG kya hai aur ACI mein policy kahan rehti hai? (Practice sawal)What is an EPG and where does policy live in ACI? (Practice question)
EPG endpoints کا logical group ہے جن پر ایک policy لگتی ہے۔ آپ policy EPG سے جوڑتے ہیں، port سے نہیں۔EPG endpoints ka logical group hai jin par ek policy lagti hai. Aap policy EPG se jorte hain, port se nahi.An EPG is a logical group of endpoints that share one policy. You attach policy to the EPG, not to the port.
❓ Bridge domain vs VRF — فرق سمجھائیں۔ (Practice سوال)Bridge domain vs VRF — farq samjhayein. (Practice sawal)Bridge domain vs VRF — explain the difference. (Practice question)
Bridge domain Layer 2 broadcast domain ہے؛ VRF Layer 3 routing domain ہے۔ ایک VRF میں کئی bridge domains ہو سکتی ہیں۔Bridge domain Layer 2 broadcast domain hai; VRF Layer 3 routing domain hai. Ek VRF mein kayi bridge domains ho sakti hain.A bridge domain is the Layer 2 broadcast domain; a VRF is the Layer 3 routing domain. One VRF can contain many bridge domains.
❓ دو EPGs کے درمیان ٹریفک block ہے۔ Default behavior کیا ہے اور اجازت کیسے دیں گے؟ (Practice سوال)Do EPGs ke darmiyan traffic block hai. Default behavior kya hai aur ijazat kaise denge? (Practice sawal)Traffic between two EPGs is blocked. What is the default behavior and how do you allow it? (Practice question)
ڈیفالٹ سب deny ہے؛ contract ہی ٹریفک کی اجازت دیتا ہے۔ آپ اسے service side (DB) پر provided اور user side (Web) پر consumed کے طور پر لگاتے ہیں۔Default sab deny hai; contract hi traffic ki ijazat deta hai. Aap isay service side (DB) par provided aur user side (Web) par consumed ke tor par lagate hain.By default everything is denied; the contract is what permits traffic. You add it as provided on the service side (DB) and consumed on the user side (Web).
❓ ACI object hierarchy نیچے سے اوپر تک سنائیں۔ (Practice سوال)ACI object hierarchy neeche se upar tak sunayein. (Practice sawal)Recite the ACI object hierarchy from bottom to top. (Practice question)
Endpoint → EPG → bridge domain → VRF → tenant۔ اگر آپ ہر object کو اس chain میں رکھ سکتے ہیں تو آپ ACI سمجھتے ہیں۔Endpoint → EPG → bridge domain → VRF → tenant. Agar aap har object ko is chain mein rakh sakte hain to aap ACI samajhte hain.Endpoint → EPG → bridge domain → VRF → tenant. If you can place every object in this chain, you understand ACI.