Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Juniper Exam JN0-683 Topic 4 Question 7 Discussion

Actual exam question for Juniper's JN0-683 exam
Question #: 7
Topic #: 4
[All JN0-683 Questions]

You are adding a server lo a tenant's network within your data center and must limit access to a specific traffic type within the tenant network without pushing all tenant traffic through a firewall.

What will satisfy this requirement?

Show Suggested Answer Hide Answer
Suggested Answer: B, C, E

Understanding ERB Architecture:

ERB (Edge Routed Bridging) architecture is a network design where the routing occurs at the edge (leaf devices) rather than in the spine devices. In a VXLAN overlay network with EVPN as the control plane, leaf devices typically act as both Layer 2 (L2) and Layer 3 (L3) VXLAN gateways.

Placement of VXLAN Gateways:

Option B: All leaf devices will have L2 VXLAN gateways to handle the bridging of VLAN traffic into VXLAN tunnels.

Option C: All leaf devices will also have L3 VXLAN gateways to route traffic between different VXLAN segments (VNIs) and external networks.

Option E: Spine devices in an ERB architecture generally do not function as VXLAN gateways. They primarily focus on forwarding traffic between leaf nodes and do not handle VXLAN encapsulation/decapsulation.

Conclusion:

Option B: Correct---All leaf devices will have L2 VXLAN gateways.

Option C: Correct---All leaf devices will have L3 VXLAN gateways.

Option E: Correct---Spine devices will not act as VXLAN gateways


Contribute your Thoughts:

Shoshana
10 hours ago
I'm leaning towards A) with the EVPN route leaking. That seems like a more elegant and scalable approach compared to the other options.
upvoted 0 times
...
Lynette
3 days ago
Hmm, I think B) is the way to go. Filter-based forwarding sounds like the perfect solution to limit access without going through a firewall.
upvoted 0 times
...
Floyd
9 days ago
Hmm, I see your point. But I still think option A) provides more flexibility and control over the traffic.
upvoted 0 times
...
Ria
11 days ago
I disagree, I believe option B) using filter-based forwarding would be a better solution.
upvoted 0 times
...
Floyd
14 days ago
I think option A) using route leaking with EVPN and a routing policy could work.
upvoted 0 times
...

Save Cancel