nerdexam
Cisco

300-420 · Question #265

An engineer is designing a WAN solution for a customer with teams in different branch locations that need to communicate. The teams also need to access enterprise applications hosted in the data…

The correct answer is D. MPLS Layer 3 VPN with one VRF for corporate access and a separate VRF for guests. An MPLS Layer 3 VPN with separate VRFs for corporate and guest access provides secure segmentation and appropriate routing for both user types, centralizing guest internet access through the data center.

WAN for Enterprise Networks

Question

An engineer is designing a WAN solution for a customer with teams in different branch locations that need to communicate. The teams also need to access enterprise applications hosted in the data center and the cloud. The customer also must provide guests with connectivity to the internet only, and the internet gateway is located in the data center. Which solution must the engineer choose?

Options

  • AMPLS Layer 3 VPN with a separate VRF for each branch location
  • BWAN connectivity from a different service provider for guests
  • Cfirewall placed in data center that filters any traffic from guests
  • DMPLS Layer 3 VPN with one VRF for corporate access and a separate VRF for guests

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    5% (1)
  • C
    5% (1)
  • D
    74% (14)

Why each option

An MPLS Layer 3 VPN with separate VRFs for corporate and guest access provides secure segmentation and appropriate routing for both user types, centralizing guest internet access through the data center.

AMPLS Layer 3 VPN with a separate VRF for each branch location

Having a separate VRF for *each branch location* would provide location isolation, but it wouldn't inherently address the distinct routing and security requirements for corporate versus guest users within the same branch or network infrastructure.

BWAN connectivity from a different service provider for guests

Providing separate WAN connectivity from a different service provider exclusively for guests would be an expensive and inefficient solution compared to leveraging the existing corporate WAN with VRFs for traffic segmentation.

Cfirewall placed in data center that filters any traffic from guests

While a firewall in the data center is crucial, simply filtering guest traffic *after* it reaches the data center does not provide the network-level segmentation across the WAN that VRFs offer, which prevents guest traffic from even traversing corporate routes before reaching the firewall.

DMPLS Layer 3 VPN with one VRF for corporate access and a separate VRF for guestsCorrect

Using an MPLS Layer 3 VPN with two distinct VRFs – one for corporate users and another for guests – allows for complete routing table separation on the WAN. The corporate VRF can provide access to internal data centers, cloud resources, and inter-branch communication, while the guest VRF can be strictly routed to the internet gateway in the data center, ensuring isolation and adherence to access policies while leveraging a single WAN infrastructure.

Concept tested: MPLS L3VPN with VRFs for network segmentation

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/mp_l3_vpns/configuration/15-mt/mp-l3-vpns-15-mt-book/mp-l3-vpns-overview.html

Topics

#MPLS L3 VPN#VRF#WAN Design#Network Segmentation

Community Discussion

No community discussion yet for this question.

Full 300-420 Practice