Cisco ACI
Overview
The Cisco ACI Integration allows Cywift to securely connect with Cisco Application Policy Infrastructure Controller (APIC) to collect fabric inventory, tenant configuration, endpoint groups, contracts, policies, access configuration, and security posture evidence.
Before starting the integration, ensure the following:
• Cisco APIC access
• Read-only APIC account
• APIC URL or IP address
• API access enabled
• Collector configured in Cywift
Step 1: Prepare Cisco ACI Access
- Log in to the Cisco APIC.
- Create a dedicated read-only user for the integration.
- Assign the required permissions for tenants and fabric objects.
- Ensure API access is enabled.
- Verify the APIC is reachable from the Cywift Collector.
Important Notes:
• Use a dedicated read-only account whenever possible
• Restrict APIC access to trusted collector IP addresses
• Avoid using shared administrator accounts
• Ensure APIC certificates are trusted if certificate validation is enabled
Step 2: Navigate to Integrations in Cywift

• Log in to the Cywift Platform
• Navigate to Integration
• Select Networking/Infrastructure
• Choose Cisco ACI
• Click Add Integration
Step 3: Add Individual Integration
Use this option when integrating a single Cisco APIC controller or cluster.

Required Fields:
• Select Individual Integration
• Select Cisco ACI from Networking/Infrastructure
• Select a configured Collector
• Enter an Integration Alias
• Select an Integration Owner
• Enter the APIC URL or IP Address
• Enter the Username
• Enter the Password
Step 4: Add Bulk Integration
Use this option to integrate multiple Cisco ACI environments.

Steps:
• Select Bulk Integration
• Download the template
• Enter the required APIC details and credentials
• Upload the completed file
• Click Test Connection
• Save the integration
Troubleshooting Tips
• Verify the APIC URL or IP address is correct
• Confirm the username and password are valid
• Check API access and account permissions
• Ensure the collector can reach the APIC
• Validate certificate settings if HTTPS validation is enabled