300-610 · Question #287
Refer to the exhibit. An engineer builds a data center network design using EVPN technology. Within the design, the fabric acts as a gateway. Traffic from host X to host Y must pass through the Cisco
The correct answer is B. routed mode. To ensure traffic between host X and host Y in an EVPN fabric passes through a Cisco ASA firewall for deep packet inspection, the engineer must deploy the firewall in routed mode.
Question
Refer to the exhibit. An engineer builds a data center network design using EVPN technology. Within the design, the fabric acts as a gateway. Traffic from host X to host Y must pass through the Cisco ASA firewall for deep packet inspection and increased security. Which firewall deployment must the engineer choose to accomplish this goal?
Exhibit
Options
- AVRF sandwich
- Brouted mode
- Cservice graph
- DVLAN stitching
How the community answered
(43 responses)- A14% (6)
- B77% (33)
- C5% (2)
- D5% (2)
Why each option
To ensure traffic between host X and host Y in an EVPN fabric passes through a Cisco ASA firewall for deep packet inspection, the engineer must deploy the firewall in routed mode.
"VRF sandwich" is an architectural pattern for inserting a firewall between VRFs, but it describes an architectural approach rather than a firewall deployment mode.
In an EVPN fabric where the fabric acts as a gateway and deep packet inspection is required between hosts, deploying the Cisco ASA firewall in routed mode is necessary. In routed mode, the firewall acts as a Layer 3 device, performing routing functions between its interfaces, allowing it to inspect traffic as it traverses from one network segment to another, fulfilling the requirement for deep packet inspection and increased security.
"Service graph" is a concept used in SDN platforms to define and automate service insertion, but it is not a firewall deployment mode.
"VLAN stitching" is a technique used in some network designs to connect VLANs, but it's not a firewall deployment mode and does not inherently provide deep packet inspection between routed segments.
Concept tested: Firewall deployment modes in data center networks
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa70/configuration/guide/config/modes.html
Topics
Community Discussion
No community discussion yet for this question.
