About This Architecture
Multi-site Cisco ACI fabric spanning Baku and Yevlakh sites, orchestrated by Nexus Dashboard Orchestrator (NDO) with stretched bridge domains and EPGs for seamless Layer 2/3 connectivity. Customer traffic from Government Security Company routes through Palo Alto and Firepower firewalls via EPG_CUSTOMER_A and EPG_CUSTOMER_B, while DMVPN routers and ASR9K edge devices provide IPsec-secured inter-site and external connectivity through L3Out policies. Spine-Leaf topology within each site converges at an Inter-Site Network (IPN) backbone, with NDO managing stretched L3Out (Tenant_Inside) and Anycast Gateway for active-active failover. This architecture demonstrates enterprise-grade multi-site fabric design with security segmentation, redundancy, and centralized orchestration. Fork and customize this topology on Diagrams.so to adapt for your own multi-site ACI deployment, firewall policies, or DMVPN configurations.