Contact Request a demo
Self-hosted · Cisco ACI control plane

Your Cisco ACI fabric, finally under control.

Day2Fabric is a self-hosted layer on top of APIC: design changes, verify they're safe, deploy them, and operate the fabric — with every ACI concept explained in plain words, so the whole team can work, not just the one expert. It ships as a containerized stack: Docker Compose — or Kubernetes with the Enterprise bundle.

For the whole teamNot just the one ACI expert.
The full lifecycleDesign, deploy, plan & operate in one place.
Self-hostedYour infrastructure, your data.
app.day2fabric.com / verifier live
Day2Fabric Policy Verifier — Reachability Matrix showing permitted and blocked flows between EPGs
Policy Verifier · Matrix mode — actual product screen
One platform · the full lifecycle

Design, deploy, plan and operate — in one place

Most tools cover one phase. Day2Fabric follows the fabric across its whole life, with a role-aware experience for everyone on the team.

Design

Model with guardrails

Lay out tenants, contracts and segmentation, validate intent with the Policy Verifier, and preview the blast radius before anything is real.

For Network Architect
Deploy

Ship changes safely

Bulk config from CSV, UI or natural language — with a diff preview, an approval step and a rollback that actually works. Read-only and demo modes keep you safe.

For Network Engineer
Plan

See the ceiling coming

Capacity and consumption reporting across ports, VLANs, endpoints and policy scale, so you forecast growth and budget before it bites.

For Capacity Planning
Operate

Stay in control

Health scoring, fault correlation, endpoint search and a full audit trail tied to sessions — across every fabric and every organization.

For Ops Team
Real screens, not renders

See it in action

Straight from the product — these are actual screens, not marketing mock-ups.

Shipped & in production

What Day2Fabric already does

Not a roadmap deck — these are the capabilities running today.

SHIPPED

Policy Verifier

Answer “can A talk to B?” the way the fabric decides — contracts, vzAny, Preferred Groups, Taboo, unenforced VRFs — in Matrix or Flow mode.

SHIPPED

Simulated Fabric Mode

A realistic, fully synthetic fabric from a seed — no APIC. Demo, train and build against it; writes persist, reset wipes them in one click.

SHIPPED

Dashboards & health

Super Admin and per-org Workspace dashboards: weighted health, fault rollups, unreachable-APIC detection, platform-wide for MSPs.

SHIPPED

Activity Monitor & audit

Every platform event logged and correlated to the session that caused it. Who did what, when and from where — with configurable retention.

SHIPPED

Schedule Activities

Plan change windows: add/remove ports to EPGs, modify contracts, with bell notifications to the right roles at the right time.

SHIPPED

Asset Inventory

Every node — ID, name, fabric, location, model, serial, OOB IP, software — in one filterable table, exportable to XLSX.

SHIPPED

Deployment Approach

Org-level policy — network-centric, application-centric or per-site — with per-location delegation that downstream features consume.

SHIPPED

Application Onboarding

A guided wizard that turns an application into tenants, EPGs, BDs and contracts — previewed in the Verifier before any APIC write.

SHIPPED

Bulk config & rollback

Define changes from CSV, UI or natural language; preview the diff, route for approval, apply through a queue, roll back cleanly.

SHIPPED

Endpoint Search

Find any IP or MAC and see exactly where it lives — tenant, app profile, EPG, VRF, contracts and DN — then pivot to it as source or destination.

SHIPPED

Capacity Planning

Interface occupancy per leaf and vPC pair, with access-port usage that excludes spine uplinks — so you see real headroom before you run out of ports.

SHIPPED

Multi-fabric & RBAC

Many fabrics and organizations under one platform, with role-based access and per-org workspaces — the foundation for MSP and large-team use.

See the full ACI & NX-OS coverage matrix →

Enterprise bundle

Built for larger, regulated networks

Everything in the platform, plus the capabilities bigger teams and security-led organizations ask for first.

Talk to us about Enterprise

SSO Enterprise

Single Sign-On through your identity provider — OIDC, SAML and LDAP (Authentik-ready). Central identity, no local accounts to manage, with a platform admin always available.

NX-OS support Extension

Manage NX-OS / standalone Nexus alongside ACI from a single platform — the same lifecycle, dashboards and audit, extended beyond APIC-managed fabrics.

see the ACI & NX-OS coverage matrix →

Zero Trust Enterprise

Microsegmentation and least-privilege policy, verified continuously. Prove and enforce a zero-trust posture across tenants, and catch the silent gaps before an auditor does.

LLM Gateway Enterprise · roadmap

On-prem AI assist, model-agnostic — Anthropic, Azure OpenAI, Bedrock or a local Ollama. ACI context is injected into the prompt; your data stays in your environment.

Audited jump-host Enterprise · roadmap

A browser-based, audited SSH gateway to the fabric — credential brokering and full session recording. For environments where direct OOB access is locked down and every keystroke must be accountable.

Priority support & SLA Enterprise

A direct line to the people who build Day2Fabric: priority response, defined SLAs and guided onboarding — plus high-assurance options like an enforced read-only service account and air-gapped offline licensing.

Questions, answered

The things people ask first

Do I have to give it access to my APIC?
No — to try it, use Simulated Fabric Mode, which needs no APIC at all. For a real fabric, Day2Fabric starts in read-only and detects write capability from your APIC roles. You flip it to read-write only when you're ready.
Does my data leave my network?
No. Day2Fabric is self-hosted: it runs on your infrastructure, keeps data in your own database, and sends no telemetry anywhere.
Does it replace APIC?
No. It's a control, comprehensibility and guardrail layer on top of APIC — not a substitute. The expert still has somewhere to go deep; everyone else gets to work safely.
How is it licensed?
Per managed fabric, across Starter, Business and Enterprise tiers. Licensing is offline and signed, so it works in air-gapped environments. Simulated fabrics don't count against your quota.
What's in the Enterprise bundle?
SSO (OIDC/SAML/LDAP), NX-OS support (extension), and Zero-Trust segmentation tooling, plus an on-prem LLM Gateway, an audited jump-host with session recording, and priority support with defined SLAs — on top of everything in the platform. Talk to us to map it to your environment.
Request a demo

See it on a real example

Tell me what's painful about your current setup and I'll tailor the walkthrough around it — on a simulated fabric, or a screen-share of yours. No slides.

  • Book a slot and tell us what you want to solve.
  • We demo it live on a realistic fabric — no setup or APIC access needed.
  • You keep the sandbox afterwards to explore on your own.
What's on your plate right now?

Got it — talk soon.

We'll reach out to schedule your demo.