Cisco ACI - Seamless Upgrade
In this lesson, you will learn how to plan and perform a Cisco ACI fabric upgrade, including the APIC cluster, spine switches, and leaf switches.
The guide explains the upgrade sequence, pre-upgrade checks, maintenance groups, controller and switch behavior during the process, and the main interface differences between older and newer APIC releases.
Table of Contents
Cisco ACI Upgrade Overview
A Cisco ACI upgrade updates the software running on the Application Policy Infrastructure Controller cluster and the fabric switches.
The objective is to move the fabric to a supported release while maintaining policy availability, endpoint connectivity, and overall fabric stability.
Although Cisco ACI is designed to support controlled rolling upgrades, every upgrade should still be treated as a planned change. The impact depends on the fabric design, redundancy, software path, connected endpoints, maintenance-group configuration, and current health of the environment.
Components Included in the Upgrade
A complete ACI fabric upgrade can involve:
- APIC controllers
- Spine switches
- Leaf switches
- Virtual APIC components when applicable
- Integrated services and external systems
- Device packages and application integrations
The exact scope depends on the current deployment and the target release.
Pre-Upgrade Checks
Before starting the upgrade, confirm that the fabric is stable and that the selected upgrade path is supported.
- Review the current APIC and switch versions.
- Confirm the supported upgrade path to the target release.
- Review the target-release documentation and known limitations.
- Check APIC cluster health and controller connectivity.
- Verify that all fabric nodes are active and reachable.
- Review active faults and resolve critical issues.
- Confirm that leaf and spine redundancy is operating correctly.
- Verify endpoint connectivity and routing before the change.
- Review maintenance groups and switch upgrade order.
- Confirm sufficient storage for firmware images.
- Take a current configuration backup.
- Document rollback and recovery procedures.
Do not begin a major software upgrade while the fabric has unresolved controller, routing, switching, storage, or policy-deployment problems.
Recommended Upgrade Sequence
The general upgrade workflow is:
- Validate fabric health and the supported upgrade path.
- Upload the required firmware image.
- Upgrade the APIC cluster.
- Verify controller-cluster stability.
- Upgrade spine and leaf switches according to the planned maintenance groups.
- Monitor node status and fabric faults throughout the process.
- Perform post-upgrade validation.
The exact sequence and supported combinations should be confirmed for the current and target ACI releases.
Upgrading the APIC Cluster
The APIC cluster should remain healthy before, during, and after the controller upgrade. Controllers are upgraded in a controlled sequence so that the cluster can continue providing policy and management services.
- Upload or select the target APIC firmware.
- Confirm that the image is available and valid.
- Review the controller upgrade plan.
- Start the APIC upgrade.
- Monitor each controller as it upgrades and rejoins the cluster.
- Confirm that the expected number of controllers is fully fit.
- Review faults before continuing to the fabric-switch upgrade.
Do not continue to the next phase until the controller cluster is stable.
Upgrading Leaf and Spine Switches
After the APIC cluster is upgraded and verified, the fabric switches can be upgraded.
Switch upgrades should be planned according to redundancy. Devices that provide redundant connectivity for the same services should not normally be upgraded simultaneously.
- Review the switch maintenance groups.
- Confirm that redundant nodes are separated appropriately.
- Start the upgrade for the selected group.
- Monitor each switch as it reloads and rejoins the fabric.
- Verify fabric adjacency and node status.
- Confirm endpoint and external-network connectivity.
- Continue with the next maintenance group.
Understanding Maintenance Groups
Maintenance groups control which switches are upgraded together. A correct grouping strategy helps preserve fabric availability during a rolling upgrade.
When designing maintenance groups:
- Separate redundant leaf switches.
- Avoid upgrading both sides of a vPC pair at the same time.
- Consider service-node and external-router connectivity.
- Preserve redundant paths toward critical workloads.
- Account for border leaf, service leaf, and remote-leaf roles.
- Review endpoint attachment and traffic paths.
The maintenance-group design should reflect the real physical and logical redundancy of the fabric.
APIC Interface Differences Between Releases
The appearance and location of some APIC menus can change between major releases. A feature available in both versions may be presented under a different menu, workflow, or interface layout.
When moving from an older release such as version 4 to a newer release such as version 6, review:
- Firmware-management pages
- Upgrade-group workflows
- Fabric inventory views
- Fault and health dashboards
- Policy configuration menus
- Operational verification pages
The video demonstrates both the upgrade workflow and selected visual differences between the releases.
Video Demonstration
The following video demonstrates the Cisco ACI upgrade workflow for the APIC cluster and fabric switches.
Post-Upgrade Verification
After the upgrade, verify both management-plane health and data-plane connectivity.
- Confirm that all APIC controllers are active and fully fit.
- Verify that all leaf and spine switches are registered and active.
- Confirm that the expected software version is installed.
- Review critical and major faults.
- Check fabric adjacencies.
- Verify endpoint learning.
- Test communication between important endpoint groups.
- Verify external routed-network connectivity.
- Check vPC status and redundant links.
- Validate service-node integrations when applicable.
- Confirm that monitoring and external integrations remain operational.
Basic Troubleshooting
An APIC Does Not Rejoin the Cluster
- Check controller connectivity and cluster status.
- Verify the controller software version.
- Review APIC faults and upgrade logs.
- Confirm that the remaining cluster members are healthy.
A Switch Does Not Return to an Active State
- Verify node reachability and fabric connectivity.
- Review firmware status and upgrade logs.
- Check LLDP and fabric-link connectivity.
- Confirm that the switch image completed successfully.
Traffic Is Affected After a Switch Upgrade
- Check vPC and port-channel status.
- Verify endpoint learning.
- Review bridge-domain and endpoint-group faults.
- Check external routing adjacencies.
- Confirm that redundant paths are restored.
Conclusion
A successful Cisco ACI upgrade requires more than installing a new firmware image. It requires a supported upgrade path, a healthy APIC cluster, correctly designed maintenance groups, redundant fabric connectivity, and comprehensive verification.
A rolling upgrade can reduce service disruption, but it should not be described as automatically risk-free or guaranteed to have no downtime. Proper planning, validation, and redundancy are essential.
After the upgrade, confirm controller health, fabric-node status, endpoint learning, external connectivity, and application communication before closing the change.
Related Reading
- Cisco CML 2 Installation and ESXi Deployment — Build a virtual lab environment for network testing and validation.
