Implementing Shared Services Across VRFs with VXLAN

Evaluate network segmentation methods using VXLAN and Cisco ACI
Answer Correct answer: D — VXLAN is needed to implement the shared service by extending Layer 2 connectivity across the VRF-separated zones.

An engineer must design a DNS service available to multiple network zones as a shared service. The network zones are deployed as VRFs within the data center network and no firewall is available for communication between VRFs. Which protocol is needed to implement the shared services?

  1. BGP
  2. OSPF
  3. ISIS
  4. VXLAN Correct Answer

Community Votes

D
67%
B
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between traditional route leaking methods and modern overlay technologies, with the common trap being the selection of standard routing protocols like BGP or OSPF which require firewall or router-based policy intervention not specified here.

This question addresses the implementation of shared services across multiple VRFs in a data center environment where direct routing is restricted. It establishes that VXLAN is the correct protocol for enabling Layer 2 connectivity and service extension between isolated network segments.

Many candidates incorrectly select BGP or OSPF because these are standard tools for route redistribution; however, they typically require explicit configuration for route leaking (like VRF-leaking) which might be considered distinct from the 'shared service' fabric approach implied by the context of modern DC design.

Community Discussion (4 comments)

zeppie 👍 1 Selected: D
The key here is that the question refers to data center network and shared services. Within a router you would be able to use for instance BGP or OSPF to perform the route leaking, but VXLAN is the answer for the data center since it supports the feature natively.
lurker8000 👍 1 Selected: D
VXLAN is correct, there was no VRF isolation requirement. The requirement was a shared service that had DNS that should be reachable to everything in the network.
Fcpoultry 👍 2
VXLAN is not an appropriate solution, as you'll allow the traffic between all VRF as there is no control access via VXLAN, so there is no restriction among all VRFs as one routing table.
Fcpoultry 👍 1 Selected: B
Route replication is supported for static, EIGRP, and OSPF routes. It is not possible to replicate routes to and from BGP, but that is not an issue because the BGP import and export method of copying routes between VRFs is available in a virtual network. https://www.cisco.com/en/US/docs/ios-xml/ios/evn/configuration/xe-3sg/evn-shared-svcs.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

VXLAN (Virtual Extensible LAN) is an overlay technology designed to extend Layer 2 domains across Layer 3 boundaries. In a data center context, VXLAN EVPN allows for the creation of a flat logical network over a stretched infrastructure, effectively bypassing VRF isolation for specific services (like DNS) when configured as a shared service instance. This aligns with the requirement to make a service available to multiple zones without relying on inter-VRF routing policies at the core.

Why the Other Options Are Wrong

BGP, OSPF, and ISIS are Layer 3 routing protocols. While BGP can be used for VRF-to-VRF route leaking (often called 'route targeting' in MPLS contexts), this typically requires specific policy configurations (like import/export lists) and is often associated with Service Provider architectures or complex multi-tenant setups. The question specifies a data center network where VXLAN is the native solution for extending broadcast domains and sharing services across tenants/zones seamlessly.

Community Comment Notes

Community discussion highlights the nuance of 'shared services.' One user noted that while BGP supports route replication, VXLAN is preferred in data centers for its native support of such features. Another commenter clarified that since there was no strict VRF isolation requirement mentioned (only that they were deployed as VRFs), VXLAN provides the necessary connectivity for the shared service to reach all zones.

Exam Strategy

When you see 'Data Center', 'Shared Services', and 'Multiple Zones/VRFs', think about Overlay technologies like VXLAN first. Traditional routing protocols handle IP reachability, but VXLAN handles the extension of L2 domains which is often how shared services (like DHCP/DNS servers) are presented to multiple tenant networks.

Frequently Asked Questions

Why not use BGP for VRF leaking?

BGP can leak routes, but it is a Layer 3 mechanism. VXLAN is an overlay that extends Layer 2, making it more suitable for presenting shared services (which often rely on broadcast/multicast) to multiple isolated segments.

Is VXLAN always required for shared services?

No, but in the context of modern Data Center designs (PCSE/PCNSE), VXLAN EVPN is the standard method for stretching L2 domains and sharing services across VRFs without complex routing policies.

More 300-610 FAQ →

Related Analysis

← Back to 300-610 Study Guide