400-007 · Question #348
Refer to the exhibit. A company named XYZ has two data centers. A recent change to the company's security policy states that the firewall must not inspect intrazone communication between the data…
The correct answer is A. Extend each VRF between the data center routers through GRE tunnel. E. Extend each VRF between the data center routers through an L3VPN service. Extending each VRF between data centers via GRE tunnel or MPLS L3VPN places inter-data-center traffic within the same logical routing domain, making it intrazone so the firewall does not inspect it.
Question
Refer to the exhibit. A company named XYZ has two data centers. A recent change to the company's security policy states that the firewall must not inspect intrazone communication between the data centers. The number of zones soon will be increased due to the company application transformation strategy. Which two solutions meet the requirements? (Choose two.)
Exhibit
Options
- AExtend each VRF between the data center routers through GRE tunnel.
- BEnable MPLS between the data center routers through an L2VPN service.
- CEnable MPLS between the data center routers through a GRE tunnel.
- DInterconnect the data center switches through an L2VPN service.
- EExtend each VRF between the data center routers through an L3VPN service.
How the community answered
(31 responses)- A45% (14)
- B29% (9)
- C16% (5)
- D10% (3)
Why each option
Extending each VRF between data centers via GRE tunnel or MPLS L3VPN places inter-data-center traffic within the same logical routing domain, making it intrazone so the firewall does not inspect it.
GRE tunnels can transport VRF-specific traffic between data center routers, effectively extending each VRF across the WAN so that communication within a given VRF is intrazone from the firewall's perspective and therefore bypasses inspection. This approach also scales well as additional VRFs (zones) are added due to application transformation, since each new VRF tunnel simply extends the new zone to both sites.
An L2VPN service provides Layer 2 bridging between sites but does not extend Layer 3 VRF instances between routers, so it does not satisfy the zone-based firewall requirement to keep intrazone routing domains consistent across data centers.
Enabling MPLS through a GRE tunnel describes a transport encapsulation technique but does not by itself extend VRF instances between data center routers to satisfy the intrazone firewall inspection bypass requirement.
Interconnecting data center switches through an L2VPN service provides Layer 2 adjacency between switches but does not extend Layer 3 VRF instances between routers, failing to meet the per-zone routing isolation requirement for zone-based firewall policy.
MPLS L3VPN services natively extend Layer 3 VRF instances between sites, ensuring that intra-VRF traffic between the two data centers is treated as intrazone by the firewall and thus not inspected. L3VPN also scales efficiently as the number of zones grows because each VRF maps directly to a separate VPN instance.
Concept tested: VRF extension methods for zone-based firewall intrazone policy
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_zbf/configuration/xe-16/sec-data-zbf-xe-16-book/zb-firewall.html
Topics
Community Discussion
No community discussion yet for this question.
