Implementing Shared Services Across VRFs with VXLAN
An engineer must design a DNS service available to multiple network zones as a shared service. The network zones are deployed as VRFs within the data center network and no firewall is available for communication between VRFs. Which protocol is needed to implement the shared services?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between traditional route leaking methods and modern overlay technologies, with the common trap being the selection of standard routing protocols like BGP or OSPF which require firewall or router-based policy intervention not specified here.
This question addresses the implementation of shared services across multiple VRFs in a data center environment where direct routing is restricted. It establishes that VXLAN is the correct protocol for enabling Layer 2 connectivity and service extension between isolated network segments.
Many candidates incorrectly select BGP or OSPF because these are standard tools for route redistribution; however, they typically require explicit configuration for route leaking (like VRF-leaking) which might be considered distinct from the 'shared service' fabric approach implied by the context of modern DC design.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
VXLAN (Virtual Extensible LAN) is an overlay technology designed to extend Layer 2 domains across Layer 3 boundaries. In a data center context, VXLAN EVPN allows for the creation of a flat logical network over a stretched infrastructure, effectively bypassing VRF isolation for specific services (like DNS) when configured as a shared service instance. This aligns with the requirement to make a service available to multiple zones without relying on inter-VRF routing policies at the core.Why the Other Options Are Wrong
BGP, OSPF, and ISIS are Layer 3 routing protocols. While BGP can be used for VRF-to-VRF route leaking (often called 'route targeting' in MPLS contexts), this typically requires specific policy configurations (like import/export lists) and is often associated with Service Provider architectures or complex multi-tenant setups. The question specifies a data center network where VXLAN is the native solution for extending broadcast domains and sharing services across tenants/zones seamlessly.Community Comment Notes
Community discussion highlights the nuance of 'shared services.' One user noted that while BGP supports route replication, VXLAN is preferred in data centers for its native support of such features. Another commenter clarified that since there was no strict VRF isolation requirement mentioned (only that they were deployed as VRFs), VXLAN provides the necessary connectivity for the shared service to reach all zones.Exam Strategy
When you see 'Data Center', 'Shared Services', and 'Multiple Zones/VRFs', think about Overlay technologies like VXLAN first. Traditional routing protocols handle IP reachability, but VXLAN handles the extension of L2 domains which is often how shared services (like DHCP/DNS servers) are presented to multiple tenant networks.
Frequently Asked Questions
Why not use BGP for VRF leaking?
BGP can leak routes, but it is a Layer 3 mechanism. VXLAN is an overlay that extends Layer 2, making it more suitable for presenting shared services (which often rely on broadcast/multicast) to multiple isolated segments.
Is VXLAN always required for shared services?
No, but in the context of modern Data Center designs (PCSE/PCNSE), VXLAN EVPN is the standard method for stretching L2 domains and sharing services across VRFs without complex routing policies.