Cisco APIC Installation and ACI Upgrade and Downgrade Guide

PDF

Cisco APIC Installation and ACI Upgrade and Downgrade Guide

Upgrade checklists

Want to summarize with AI?

Log in

Check these items before you upgrade Cisco APIC.


For information about other check rules, see the ee the ACI Pre-Upgrade Validation Script.

  • If you are upgrading to Cisco APIC release 4.2(6o), 4.2(7l), 5.2(1g), or later, ensure that any VLAN encapsulation blocks that you are explicitly using for leaf switch front panel VLAN programming are set as "external (on the wire)." If these VLAN encapsulation blocks are instead set to "internal," the upgrade causes the front panel port VLAN to be removed, which can result in a datapath outage.

  • When Cisco APIC is upgraded from Cisco APIC 4.0 or earlier to 5.1(1) or later, the Service Graph is re-rendered. This will result in traffic disruption until the re-rendering is completed, if vzAny-to-vzAny contract with service graph and another contract with service graph use the same service EPG.

  • Prior to APIC version 5.0, when you have the following configuration, traffic in the provider-to-consumer direction was allowed incorrectly. This was fixed starting from APIC 5.0. As a result, the incorrectly allowed traffic will stop working after the upgrade from a pre-5.0 version to a post-5.0 version. If the provider-to-consumer direction should not be dropped, configure a contract filter in that direction accordingly.

    • Unidirectional contract (only consumer to provider filter without "Apply Both Direction" flag)

    • Shared Service (contract provider and consumer are in different VRFs)

    • L3Out EPG is the provider

    • L3Out EPG has 0.0.0.0/0 with "Shared Security Import Subnet"

    • The provider IP of the traffic is classified to the L3Out subnet 0.0.0.0/0

    • The consumer VRF has Preferred Group (PG) enabled

    • The consumer EPG is included in PG

    • The provider VRF is on the consumer leaf

  • Prior to APIC version 5.0, when you have the following configuration, traffic in the provider-to-consumer direction was allowed incorrectly even though the configuration is invalid. The "Shared Security Import Subnet" scope is a mandatory configuration. This was fixed starting from APIC 5.0. As a result, the incorrectly allowed traffic will stop working after the upgrade from a pre-5.0 version to a post-5.0 version.

    • Shared Service (contract provider and consumer are in different VRFs)

    • L3Out EPG is the provider

    • The "Shared Security Import Subnet" scope is missing on all non-0.0.0.0/0 subnets in the L3Out EPG

    • Those non-0.0.0.0/0 subnets have the "External Subnet for the External EPG" scope

    • The provider IP of the traffic is classified to one of those non-0.0.0.0/0 subnets in the L3Out EPG

  • Global AES Encryption must be enabled to upgrade to APIC release 6.1(2) or newer.