Question 1
A financial institution is deploying a Cisco ACI Multi-Pod fabric. To meet regulatory requirements, all inter-pod traffic traversing the IPN must be encrypted. The IPN is comprised of Nexus 7700 switches which do not natively support CloudSec. Which ACI feature must be configured on the spine switches to meet this requirement?
Answer and explanation
Correct answer: B
When the IPN devices do not support CloudSec, the recommended and supported method for encrypting inter-pod traffic is to use MACsec (802.1AE) on the physical links between the ACI spine switches and the IPN. This provides hop-by-hop Layer 2 encryption. CloudSec is used for ACI Multi-Site encryption over the ISN. L3Out with IPsec is a valid encryption method but is more complex and typically used for connecting to external networks, not for the IPN itself. GDOI is not the standard mechanism for IPN encryption in ACI.