Avoiding Firewall Intrazone Inspection in Dual Data Centers

Answer Correct answer: A, B — Use GRE tunnels with VRFs or MPLS L2VPN services to bypass firewall inspection.

Refer to the exhibit. A company named XYZ has two data centers. A recent change to the company’s security policy states that the firewall must not inspect intrazone communication between the data centers. The number of zones soon will be increased due to the company application transformation strategy. Which two solutions meet the requirements? (Choose two.) - image

  1. Extend each VRF between the data center routers through GRE tunnel. Correct Answer
  2. Enable MPLS between the data center routers through an L2VPN service. Correct Answer
  3. Enable MPLS between the data center routers through a GRE tunnel.
  4. Interconnect the data center switches through an L2VPN service.
  5. Extend each VRF between the data center routers through an L3VPN service.

Community Votes

BE
50%
CE
25%
AE
25%

50% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to design a scalable network that avoids a specific security control (firewall) by leveraging Layer 3 and Layer 2 transport technologies.

To prevent firewall inspection of intrazone traffic between data centers, the network must route traffic outside the security perimeter. The correct solutions involve using GRE tunnels with VRFs or MPLS L2VPNs to bypass the firewall.

Many candidates choose options that keep traffic within the same zone or through the firewall, such as L3VPN without tunneling, failing to realize these still traverse the inspected path.

Community Discussion (6 comments)

Devsin2000 👍 1 Selected: AE
A tunnel that traverses through the firewalls is the answer - hence A & E
sandccie 👍 1 Selected: BE
BE. MPLS with L2VPN (VPLS, EoMPLS, EVPN) extends multiple VLANs and is scalable. MPLS L3VPN extends multiple VRFs across datacenter.
Devsin2000 👍 1 Selected: AE
A tunnel through the firewall is perhaps the optimal way of avoiding it. A GRE E L3VPN
kalulosu 👍 1 Selected: BE
I think correct answers are B & E
Weltbuerger 👍 2 Selected: BE
Why not deploy MPLS via L2VPN? More scalable than extending VRFs via L3VPNs?
JCGO 👍 2 Selected: CE
... number of VRF's will be increased. So scalable solution needed. I would got for GRE + LDP between routers and BGP VPNv4. L2 per VRF or GRE per VRF will not scale

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct The core requirement is to stop the firewall from inspecting traffic between the two data centers. This implies the traffic must physically or logically bypass the firewall's inspection engine. Option A (GRE over VRF) creates a tunnel that encapsulates the traffic, effectively making it 'transit' traffic rather than local intrazone traffic, thus avoiding deep packet inspection if the firewall is not configured to terminate the tunnel. Option B (MPLS L2VPN) extends the Layer 2 domain directly between routers/switches via the provider cloud, completely bypassing the customer-edge firewalls for this specific traffic flow.

Why the Other Options Are Wrong Option C is incorrect because enabling MPLS requires a signaling protocol like LDP or RSVP-TE; you cannot simply 'enable MPLS' through a GRE tunnel as GRE does not carry MPLS labels natively without additional encapsulation complexities not implied here. Option D is less optimal than B for router-to-router interconnects described in typical WAN designs, and extending switches might introduce spanning tree issues across sites. Option E (L3VPN) typically routes traffic through the provider edge, which often connects back into the customer's routing infrastructure where firewalls reside, potentially still subjecting it to policy unless specifically tunneled.

Community Comment Notes The community discussion highlights the scalability aspect due to increasing zones. As JCGO noted, "So scalable solution needed... L2 per VRF or GRE per VRF will not scale," suggesting a preference for transport mechanisms that handle multiple VRFs/VLANs efficiently. Weltbuerger and sandccie support BE, arguing that MPLS L2VPN is more scalable for extending multiple VLANs compared to individual GRE tunnels per VRF.

Official Reference

Exam Strategy

When asked to avoid firewall inspection, look for solutions that create a direct transport path (tunnel or L2 extension) that does not terminate at the firewall. GRE tunnels are a classic way to hide payload content from intermediate devices.

Frequently Asked Questions

Why doesn't L3VPN avoid firewall inspection?

L3VPN routes traffic through provider edges, which often feed back into customer sites where firewalls sit. Unless tunneled, it may still be inspected.

Is GRE better than L2VPN for scaling?

L2VPN (like EVPN/VPLS) scales better for many VLANs. GRE requires a separate tunnel per VRF, which becomes complex to manage at scale.

Related Analysis

← Back to 400-007 Study Guide