Segmenting Same VLAN Systems with Legacy IPs

Answer Correct answer: C — Use VACLs on data center switches to segment traffic within the same VLAN without changing hard-coded IP addresses.

A customer has a functional requirement that states HR systems within a data center should be segmented from other systems that reside in the same data center and same VLAN. The systems run legacy applications by using hard-coded IP addresses. Which segmentation method is suitable and scalable for the customer?

  1. data center perimeter firewalling
  2. routed firewalls
  3. VACLs on data center switches Correct Answer
  4. transparent firewalling

Community Votes

C
57%
D
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of Layer 2 vs Layer 3 segmentation constraints when legacy applications prevent IP reconfiguration.

Determines the correct segmentation method for HR systems in the same VLAN using legacy hard-coded IPs. Establishes that VACLs provide necessary Layer 2 isolation without requiring IP changes.

Choosing transparent firewalls (D) due to their ability to bridge networks, ignoring that they typically require distinct subnets or routed interfaces for effective policy enforcement and scalability in this specific context.

Community Discussion (5 comments)

Devsin2000 👍 2 Selected: C
-Transparent firewall bridge two VLANs but same subnet - it's a technique . But in this case there is only one VLAN, and hence VACL is the right option.
kalulosu 👍 1 Selected: C
I think ans is C. VACLs (VLAN Access Control Lists) are an effective way to control and segment specific traffic, even within the same VLAN. It is particularly suitable for legacy systems that use hard- coded IP addresses.
noxkrugger 👍 1 Selected: C
Yes C is right
noxkrugger 👍 1
C is right.
Charles2024 👍 3 Selected: D
Needs to be scalable - so transparent fw. if it didnt have scalable then vacl

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

VACLs (VLAN Access Control Lists) are the suitable choice because they operate at Layer 2, allowing traffic filtering within a single broadcast domain (VLAN). Since the legacy applications use hard-coded IP addresses, moving them to a different subnet is not feasible. VACLs can segment traffic based on MAC addresses or IP headers within the same VLAN, providing the required isolation between HR and other systems.

Why the Other Options Are Wrong

Data center perimeter firewalling (A) protects the boundary of the data center but does not provide internal micro-segmentation. Routed firewalls (B) require Layer 3 routing, which implies changing the network topology and IP addressing, violating the constraint of hard-coded IPs. Transparent firewalls (D) act as a bridge; while they don't change IP addresses, they often complicate scaling and management compared to switch-based VACLs for intra-VLAN segmentation, especially when the goal is simple access control within the existing infrastructure.

Community Comment Notes

Community members like Charles2024 initially leaned towards transparent firewalls, citing scalability, but Devsin2000 correctly pointed out that transparent firewalls bridge VLANs/subnets, whereas VACLs are native to the switch layer for intra-VLAN control. kalulosu and noxkrugger confirmed VACLs as the right option for handling legacy systems within the same VLAN.

Official Reference

Exam Strategy

When faced with legacy systems that cannot have their IP addresses changed, prioritize solutions that operate at Layer 2 or do not require network re-architecting. Always evaluate if the proposed solution actually requires modifying the endpoint configuration before selecting it.

Frequently Asked Questions

Why not transparent firewalls for same VLAN?

Transparent firewalls bridge networks but may not offer the same granular, scalable control within a single VLAN as VACLs, especially for legacy apps.

Can VACLs filter by IP?

Yes, VACLs can match on IP addresses, protocols, and ports, making them effective even with hard-coded IPs in the same subnet.

Related Analysis

← Back to 400-007 Study Guide