Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2VirtualizationMedium
A network engineer is configuring a virtual switch on a hypervisor. The goal is to ensure that virtual machines (VMs) connected to this virtual switch can only communicate with other VMs within the same virtual network segment, and cannot access other virtual network segments or the physical network directly, even if they are on the same physical host. Which virtual switching concept describes this type of isolated Layer 2 forwarding?
- APrivate VLAN (PVLAN)
- BPort Mirroring
- CPromiscuous Mode
- DExternal Network Access
Show answer & explanationAnswer & explanation
Correct answer: A. Private VLAN (PVLAN)
Private VLANs (PVLANs) are a virtual switching concept that provides Layer 2 isolation between ports within the same VLAN. By assigning VMs to different PVLAN types (isolated, community, primary), an administrator can restrict communication between VMs even if they are on the same virtual switch, ensuring that VMs can only communicate with other VMs within their designated private VLAN or with specific uplink ports.
Why the other options are wrong
- B. Port mirroring copies traffic to a monitoring port and is not related to isolation.
- C. Promiscuous mode allows a VM to see all traffic on a virtual switch, which is the opposite of isolation.
- D. External network access typically means connecting to the physical network, not isolating VMs from each other.
Private VLAN (PVLAN) in Virtual Switching
A virtual switching feature that provides Layer 2 isolation between ports or VMs within the same VLAN, restricting communication.
- Uses primary, isolated, and community VLAN types for granular control.
- Isolated ports can only communicate with the primary VLAN uplink.
- Community ports can communicate with each other and the primary VLAN uplink.
Memory trick: PVLANs: Private VLANs Lock Down VM Communication.