Segmenting Same VLAN Systems with Legacy IPs
A customer has a functional requirement that states HR systems within a data center should be segmented from other systems that reside in the same data center and same VLAN. The systems run legacy applications by using hard-coded IP addresses. Which segmentation method is suitable and scalable for the customer?
Community Votes
57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of Layer 2 vs Layer 3 segmentation constraints when legacy applications prevent IP reconfiguration.
Determines the correct segmentation method for HR systems in the same VLAN using legacy hard-coded IPs. Establishes that VACLs provide necessary Layer 2 isolation without requiring IP changes.
Choosing transparent firewalls (D) due to their ability to bridge networks, ignoring that they typically require distinct subnets or routed interfaces for effective policy enforcement and scalability in this specific context.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
VACLs (VLAN Access Control Lists) are the suitable choice because they operate at Layer 2, allowing traffic filtering within a single broadcast domain (VLAN). Since the legacy applications use hard-coded IP addresses, moving them to a different subnet is not feasible. VACLs can segment traffic based on MAC addresses or IP headers within the same VLAN, providing the required isolation between HR and other systems.Why the Other Options Are Wrong
Data center perimeter firewalling (A) protects the boundary of the data center but does not provide internal micro-segmentation. Routed firewalls (B) require Layer 3 routing, which implies changing the network topology and IP addressing, violating the constraint of hard-coded IPs. Transparent firewalls (D) act as a bridge; while they don't change IP addresses, they often complicate scaling and management compared to switch-based VACLs for intra-VLAN segmentation, especially when the goal is simple access control within the existing infrastructure.Community Comment Notes
Community members like Charles2024 initially leaned towards transparent firewalls, citing scalability, but Devsin2000 correctly pointed out that transparent firewalls bridge VLANs/subnets, whereas VACLs are native to the switch layer for intra-VLAN control. kalulosu and noxkrugger confirmed VACLs as the right option for handling legacy systems within the same VLAN.Official Reference
- https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/configuration/vlan_security/vlan_security_book/vlan-security.html
- https://www.cisco.com/c/en/us/support/docs/security/firepower-next-generation-firewalls/200627-Transparent-Firewall-Mode-on-Firepower-NGFW.html
- https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/security/config-guide/b_sec_93xx_cg/nx-os-security-config-guide-93xx.html
Exam Strategy
When faced with legacy systems that cannot have their IP addresses changed, prioritize solutions that operate at Layer 2 or do not require network re-architecting. Always evaluate if the proposed solution actually requires modifying the endpoint configuration before selecting it.
Frequently Asked Questions
Why not transparent firewalls for same VLAN?
Transparent firewalls bridge networks but may not offer the same granular, scalable control within a single VLAN as VACLs, especially for legacy apps.
Can VACLs filter by IP?
Yes, VACLs can match on IP addresses, protocols, and ports, making them effective even with hard-coded IPs in the same subnet.