Broadcom-VMware
3V0-25.25 · Question #54
A customer wants to use VRF-lite-like isolation for multiple tenants while sharing the same physical uplinks and Edge cluster. Which NSX construct should be used?
The correct answer is A. Separate Tier-0 gateways per tenant. Multiple Tier-0 gateways provide true routing table isolation, functionally equivalent to VRFs. Tier-1 gateways do NOT provide full L3 isolation from upstream routing domains.
Configure NSX-T Infrastructure
Question
A customer wants to use VRF-lite-like isolation for multiple tenants while sharing the same physical uplinks and Edge cluster. Which NSX construct should be used?
Options
- ASeparate Tier-0 gateways per tenant
- BTier-1 gateways with NAT
- CVLAN-backed segments with separate dvSwitches
- DSecurity Groups with tags
How the community answered
(17 responses)- A82% (14)
- C12% (2)
- D6% (1)
Explanation
Multiple Tier-0 gateways provide true routing table isolation, functionally equivalent to VRFs. Tier-1 gateways do NOT provide full L3 isolation from upstream routing domains.
Topics
#multi-tenancy#VRF-lite#Tier-0 gateway#tenant isolation
Community Discussion
No community discussion yet for this question.