nerdexam
HP

HPE7-A04 · Question #56

Two VMs on the same ESXi host are assigned to an isolated VLAN 2001 (primary VLAN 1001). The host connects to an HPE Aruba CX 10000 switch on an access port. The switch supports the same PVLAN…

The correct answer is A. Egress policy on VLAN 1001. Option A is correct because on HPE Aruba CX switches, PVLAN traffic is classified at ingress under the secondary VLAN (isolated VLAN 2001), so no ingress policy tied to the primary VLAN 1001 is triggered - but when the switch forwards traffic outbound (egress), it does so in…

Designing for Virtualization, Automation, and Security

Question

Two VMs on the same ESXi host are assigned to an isolated VLAN 2001 (primary VLAN 1001). The host connects to an HPE Aruba CX 10000 switch on an access port. The switch supports the same PVLAN settings. VM 1 sends traffic to VM 2. Which policy or policies does the switch apply (assuming that they exist)?

Options

  • AEgress policy on VLAN 1001
  • BNo policies because the traffic remains local to the ESXi host
  • CIngress and egress policy on VLAN 1001
  • DIngress policy on VLAN 1001

How the community answered

(37 responses)
  • A
    59% (22)
  • B
    5% (2)
  • C
    14% (5)
  • D
    22% (8)

Explanation

Option A is correct because on HPE Aruba CX switches, PVLAN traffic is classified at ingress under the secondary VLAN (isolated VLAN 2001), so no ingress policy tied to the primary VLAN 1001 is triggered - but when the switch forwards traffic outbound (egress), it does so in the context of primary VLAN 1001, so the egress policy on 1001 is applied.

Option B is wrong because isolated PVLANs prohibit direct VM-to-VM communication even on the same host - the traffic must traverse the physical switch to reach a promiscuous port (router/gateway) and be forwarded back, so the switch absolutely processes this traffic. Options C and D are wrong because no ingress policy on VLAN 1001 fires at all: the ingress lookup happens against the secondary VLAN (2001), not the primary, so policies bound to 1001 are not evaluated on the way in.

Memory tip: Think "PVLAN = Primary at Exit" - the Primary VLAN policy only kicks in on the way out (egress), because that's when the switch maps the traffic back to the primary VLAN context for forwarding decisions.

Topics

#PVLAN#private VLAN#CX 10000#traffic policies

Community Discussion

No community discussion yet for this question.

Full HPE7-A04 Practice