nerdexam
Cisco

350-601 · Question #399

An engineer must configure a VDS port group using APIC policy. The requirements are for the frames to be mapped to a particular Layer 2 network and for the virtual machine assigned to the port group t

The correct answer is C. port binding D. promiscuous mode. To configure a VDS port group for a VM to receive all frames and be mapped to a specific Layer 2 network via APIC policy, promiscuous mode must be enabled and appropriate port binding must be configured.

Network

Question

An engineer must configure a VDS port group using APIC policy. The requirements are for the frames to be mapped to a particular Layer 2 network and for the virtual machine assigned to the port group to receive all frames passed on the virtual switch. Which two settings must be used to meet these requirements? (Choose two.)

Options

  • Aforged transmits
  • BVMDirectPath
  • Cport binding
  • Dpromiscuous mode
  • EVLAN

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    83% (20)
  • E
    4% (1)

Why each option

To configure a VDS port group for a VM to receive all frames and be mapped to a specific Layer 2 network via APIC policy, promiscuous mode must be enabled and appropriate port binding must be configured.

Aforged transmits

Forged transmits is a security policy that determines whether the VM guest operating system is allowed to send frames with a MAC address different from its own, which is unrelated to receiving all frames or mapping to a Layer 2 network.

BVMDirectPath

VMDirectPath, also known as PCIe Passthrough, allows a VM to directly access a physical PCIe device, bypassing the hypervisor's virtual switch, which is for direct hardware access, not for general virtual switch network configuration.

Cport bindingCorrect

Port binding (static or dynamic) is a crucial VDS setting that determines how a virtual machine's network adapter connects to a specific port on the virtual switch. This binding ensures that the VM is correctly associated with the configured Layer 2 network (e.g., VLAN or EPG) defined by the port group policy within APIC.

Dpromiscuous modeCorrect

Promiscuous mode, when enabled on a VDS port group, allows a virtual machine to receive all traffic traversing the virtual switch to which the port group belongs, not just traffic destined for its own MAC address. This directly addresses the requirement for the VM to receive 'all frames passed on the virtual switch'.

EVLAN

While VLANs are fundamental for defining a Layer 2 network, 'VLAN' itself is the network segmentation mechanism, whereas 'port binding' is the setting that associates the VM with that VLAN-configured port group, and 'promiscuous mode' handles the 'receive all frames' requirement.

Concept tested: VMware VDS port group settings (Promiscuous mode, Port Binding)

Source: https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.networking.doc/GUID-88C8382F-EB4B-4E38-958C-5381676D6EB0.html

Topics

#APIC Policy#VDS Port Group#Promiscuous Mode#ACI-VMM Integration

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice