QuestionQ63

Data Center Multitenancy and Security

You are adding a server to a tenant network in your data center and must restrict access for a particular traffic type within that tenant network, without sending all tenant traffic through a firewall.

What satisfies this requirement?

  • A Use filter-based forwarding.
  • B Put the new server on a unique subnet within the tenant’s network.
  • C Use route leaking with EVPN and a routing policy.
  • D Use a static route in the tenant VRF with a firewall as the next hop for traffic to the new server.
Explanation

Filter-based forwarding applies a firewall filter that matches specified packet characteristics, such as protocol or port, and redirects only the matching traffic to a selected routing instance, next hop, firewall, or security device. Traffic that does not match continues on its normal forwarding path.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!