Refer to the exhibit. You want the vSRX device to inspect traffic between the VMs.
Which two actions must you take to accomplish this task?
VMs in the same VLAN on the same virtual switch can exchange same-subnet traffic directly through Layer 2, bypassing the vSRX. Placing the VM-facing connections in separate VLANs and separate vSwitches creates distinct Layer-2 segments, requiring traffic between the VMs to traverse the vSRX for routing and inspection. Juniper documentation also notes that separate VLAN tags create separate broadcast domains on a vSwitch.
Community Discussion