nerdexam
HP

HPE7-A04 · Question #38

You are designing a network based on HPE Aruba CX 10000 switches. Which is a valid reason to recommend manually pinning two VRFs to the same DSM?

The correct answer is D. That switch leaks routes between those VRFs. On the HPE Aruba CX 10000, each DSM (Data Services Module, powered by an AMD Pensando DPU) maintains its own forwarding tables, and inter-VRF route leaking requires both VRFs to reside on the same DSM - the hardware cannot perform cross-DSM inter-VRF lookups. This makes D the…

Designing Data Center Network Architectures

Question

You are designing a network based on HPE Aruba CX 10000 switches. Which is a valid reason to recommend manually pinning two VRFs to the same DSM?

Options

  • AThat switch forwards traffic in both VRFs to a third-party firewall for routing
  • BYou have selected this switch to act as the border leader for a multi-fabric EVPN VXLAN design
  • CYou have planned similar policies for those VRFs and want to minimize the load on the switches'
  • DThat switch leaks routes between those VRFs

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    4% (1)
  • C
    25% (6)
  • D
    63% (15)

Explanation

On the HPE Aruba CX 10000, each DSM (Data Services Module, powered by an AMD Pensando DPU) maintains its own forwarding tables, and inter-VRF route leaking requires both VRFs to reside on the same DSM - the hardware cannot perform cross-DSM inter-VRF lookups. This makes D the only architecturally valid reason to manually co-locate two VRFs on a single DSM.

Why the distractors fail:

  • A (third-party firewall routing): Traffic leaving the switch toward an external firewall doesn't require both VRFs to share a DSM. The firewall handles the inter-VRF routing externally, so DSM placement is irrelevant.
  • B (border leader for multi-fabric EVPN VXLAN): The border leader role is a control-plane function. There is no hardware requirement that VRFs serving this role share a DSM.
  • C (similar policies): Policy similarity is not a valid technical reason to pin VRFs together. DSMs process independently, so consolidating similar policies onto one DSM doesn't reduce overall switch load - it may actually reduce parallelism.

Memory tip: Think "leakers must live together." If two VRFs need to share routes (leak), they must share a DSM - the Pensando hardware resolves inter-VRF forwarding locally within a single DSM context.

Topics

#CX 10000#VRF pinning#DSM#route leaking

Community Discussion

No community discussion yet for this question.

Full HPE7-A04 Practice