nerdexam
Broadcom-VMware

2V0-13.25 · Question #106

An architect is working on a VMware Cloud Foundation (VCF) architecture design and identified the following requirements: - The organization is using a third-party virtual appliance that does not…

The correct answer is B. Connect the virtual appliance to a VLAN-backed segment and configure NSX bridging to allow. According to the VMware Cloud Foundation 9.0.2 Design Guide (NSX Bridging and Layer 2 Connectivity), when workloads or appliances require Layer 2 adjacency with physical network devices and do not support overlay encapsulation (Geneve), NSX Edge bridging is the validated The…

Section 2 – Design VMware Cloud Foundation Solutions

Question

An architect is working on a VMware Cloud Foundation (VCF) architecture design and identified the following requirements:

  • The organization is using a third-party virtual appliance that does

not support overlay networks.

  • The virtual appliance must reside on the same L2 domain as an

external physical firewall.

  • The virtual appliance also needs access to workloads that are

currently hosted on overlay segments provided by NSX. Which design decision should the architect make to meet these requirements?

Options

  • ARequest the third-party vendor to certify the virtual appliance for NSX Overlay segments.
  • BConnect the virtual appliance to a VLAN-backed segment and configure NSX bridging to allow
  • CPlace the virtual appliance and all workloads on VLAN-backed segments.
  • DConnect the virtual appliance to an overlay-backed segment and use static routes to the firewall.

How the community answered

(38 responses)
  • A
    13% (5)
  • B
    47% (18)
  • C
    32% (12)
  • D
    8% (3)

Explanation

According to the VMware Cloud Foundation 9.0.2 Design Guide (NSX Bridging and Layer 2 Connectivity), when workloads or appliances require Layer 2 adjacency with physical network devices and do not support overlay encapsulation (Geneve), NSX Edge bridging is the validated The documentation states: "The bridge functionality extends an overlay segment into a VLAN identified by a VLAN ID on an uplink of the NSX Edge. This enables Layer 2 connectivity between virtual machines on NSX overlay segments and physical workloads on VLAN-backed networks." By connecting the third-party appliance to a VLAN-backed segment and configuring NSX bridging, the appliance gains direct L2 connectivity to the firewall, while the workloads on overlay segments can still communicate seamlessly through the bridge. This approach maintains the logical separation of NSX networks while satisfying L2 adjacency requirements, a common design pattern for integrating non-overlay-capable systems.

Topics

#NSX bridging#VLAN segments#overlay networks#L2 domain

Community Discussion

No community discussion yet for this question.

Full 2V0-13.25 Practice