Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2VirtualizationHard

A network security team is implementing a virtual firewall solution within a data center to segment traffic between different application tiers (e.g., web, application, database). They need to ensure that the virtual firewall can inspect traffic between VMs residing on the same hypervisor without forcing the traffic out to a physical firewall. Which virtual switching capability allows for this 'Hairpinning' or 'Inter-VM' traffic inspection?

  1. AVirtual PortChannel (vPC)
  2. BPrivate VLAN (PVLAN) isolation
  3. CPort Mirroring (SPAN/RSPAN)
  4. DDistributed Virtual Switch (DVS) with Service Chaining
Show answer & explanation

Correct answer: D. Distributed Virtual Switch (DVS) with Service Chaining

A Distributed Virtual Switch (DVS) combined with service chaining capabilities allows for traffic redirection to virtual network appliances like firewalls and load balancers, even for inter-VM traffic on the same hypervisor. This enables the virtual firewall to inspect traffic without it leaving the hypervisor, often referred to as 'hairpinning' or 'east-west' traffic inspection.

Why the other options are wrong

  • A. vPC provides link aggregation and multi-chassis redundancy for physical switches, unrelated to inter-VM traffic inspection by a virtual firewall.
  • B. PVLANs provide Layer 2 isolation within a VLAN, preventing communication between specific ports, not enabling inspection by a firewall.
  • C. Port Mirroring (SPAN/RSPAN) copies traffic for analysis but does not allow for active inspection and policy enforcement by a firewall.

DVS Service Chaining

Distributed Virtual Switch (DVS) Service Chaining is a capability that allows administrators to define a sequence of network services (e.g., firewall, load balancer, IDS) that traffic must traverse. This enables virtual network appliances to inspect and process inter-VM traffic on the same hypervisor, optimizing traffic flow and enforcing policies.

  • Redirects traffic to virtual network appliances.
  • Enables inspection of inter-VM traffic on the same host.
  • Optimizes traffic flow by keeping it local to the hypervisor.

Memory trick: DVS Chains Services, VMs See No Outside Walls.

More Virtualization questions