300-320 · Question #171
A network engineer is implementing virtualization into the enterprise network. Which system should be used to address policy enforcement at the distribution layer?
The correct answer is C. integrated firewall services. In a virtualized enterprise campus, the distribution layer is the natural policy enforcement point between VRFs and VLANs. Integrated firewall services-such as Cisco's Firewall Service Module (FWSM) or integrated service blades installed directly in distribution-layer…
Question
A network engineer is implementing virtualization into the enterprise network. Which system should be used to address policy enforcement at the distribution layer?
Options
- ACisco IOS based firewall
- Bmultilayer switches
- Cintegrated firewall services
- Didentity services engine
- Eintrusion protection systems
How the community answered
(19 responses)- A5% (1)
- B11% (2)
- C79% (15)
- E5% (1)
Explanation
In a virtualized enterprise campus, the distribution layer is the natural policy enforcement point between VRFs and VLANs. Integrated firewall services-such as Cisco's Firewall Service Module (FWSM) or integrated service blades installed directly in distribution-layer multilayer switches-allow stateful firewall inspection and policy enforcement without requiring traffic to hairpin to a separate appliance. This keeps enforcement in-line at the distribution tier with minimal latency. A standalone IOS-based firewall would require separate hardware and off-path routing. Multilayer switches perform routing and some ACL-based filtering but lack stateful firewall capability. An Identity Services Engine (ISE) handles authentication and authorization policy, not traffic-path firewall enforcement. IPS modules address threat detection, not policy enforcement between virtualization segments.
Topics
Community Discussion
No community discussion yet for this question.