Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

VMware 3V0-25.25 Exam - Topic 1 Question 6 Discussion

An administrator is configuring an NSX segment used by a nested hypervisor deployment where an ESXi VM runs on an ESXi host and multiple VMs run inside the ESXi VM. Which segment profile must be created to satisfy the request?
C) MAC Discovery
A) IP Discovery
B) Security
D) Spoof Guard

VMware 3V0-25.25 Exam - Topic 1 Question 6 Discussion

Actual exam question for VMware's 3V0-25.25 exam
Question #: 6
Topic #: 1
[All 3V0-25.25 Questions]

An administrator is configuring an NSX segment used by a nested hypervisor deployment where an ESXi VM runs on an ESXi host and multiple VMs run inside the ESXi VM. Which segment profile must be created to satisfy the request?

Show Suggested Answer Hide Answer
Suggested Answer: C

Comprehensive and Detailed 250 to 350 words of Explanation From VMware Cloud Foundation (VCF) documents:

Nested virtualization---where a hypervisor like ESXi is run as a virtual machine---imposes unique challenges on the virtual networking layer. In a standard VCF environment, an NSX segment port expects to see exactly one MAC address: the MAC address assigned to the VM's vNIC.

When you run a nested hypervisor, that single vNIC now acts as an 'uplink' for multiple 'inner' virtual machines. Consequently, traffic originating from that single nested ESXi VM will contain many different source MAC addresses (one for each nested VM). By default, the NSX/VDS security and switching logic will drop this traffic because it appears as MAC Spoofing---packets are arriving from a port with source MACs that do not match the port's registered ID.

To support this, a MAC Discovery Segment Profile must be configured and applied to the segment. Within this profile, the administrator must enable MAC Learning. MAC Learning allows the NSX virtual switch to 'learn' and permit multiple MAC addresses on a single logical port. Without this, only the primary MAC of the nested ESXi host would be allowed, and all nested VMs would lose connectivity to the rest of the network.

In VCF 5.x and 9.0 documentation, this is a standard requirement for 'Lab-on-a-Lab' designs or development environments. While IP Discovery (Option A) and Spoof Guard (Option D) are important for maintaining the IP-to-MAC binding and preventing IP theft, they do not address the fundamental Layer 2 requirement of allowing multiple MAC identities on a single port. Therefore, MAC Discovery with MAC learning enabled is the verified profile choice for nested hypervisor support.

===========


Contribute your Thoughts:

0/2000 characters
Cecilia
26 days ago
MAC Discovery might be useful too, but not sure if it's essential.
upvoted 0 times
...
Marylyn
1 month ago
Wait, can you really run VMs inside a VM? Sounds tricky!
upvoted 0 times
...
Tori
1 month ago
I think Security is more important in this case.
upvoted 0 times
...
Gracie
1 month ago
Definitely need the IP Discovery profile for that setup.
upvoted 0 times
...
Carma
2 months ago
I’m leaning towards IP Discovery because it seems to be about managing IPs in a nested setup, but I could be mixing it up with another question we did.
upvoted 0 times
...
Penney
2 months ago
I feel like Spoof Guard could be relevant too, especially with nested deployments, but I don't remember the specifics.
upvoted 0 times
...
Helene
2 months ago
I remember practicing a question about segment profiles, and I think Security was important for protecting the VMs, but I can't recall if it applies here.
upvoted 0 times
...
Shalon
2 months ago
I think we might need to look at the MAC Discovery profile since it deals with nested VMs, but I'm not entirely sure.
upvoted 0 times
...
Yuonne
2 months ago
I feel like Security profiles are essential in any deployment, but I wonder if they specifically apply here.
upvoted 0 times
...
Fannie
2 months ago
Spoof Guard sounds familiar, but I can't recall if it directly relates to nested hypervisors. I might be mixing it up with security settings.
upvoted 0 times
...
Tanesha
3 months ago
I remember practicing a question similar to this, and I think IP Discovery was important for identifying VMs in a nested setup.
upvoted 0 times
...
Pearly
3 months ago
I think we might need to focus on the MAC Discovery profile since it's about nested VMs, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel