Avoiding Firewall Intrazone Inspection in Dual Data Centers
Refer to the exhibit. A company named XYZ has two data centers. A recent change to the company’s security policy states that the firewall must not inspect intrazone communication between the data centers. The number of zones soon will be increased due to the company application transformation strategy. Which two solutions meet the requirements? (Choose two.) - 
Community Votes
50% of anonymous learners picked answer BE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to design a scalable network that avoids a specific security control (firewall) by leveraging Layer 3 and Layer 2 transport technologies.
To prevent firewall inspection of intrazone traffic between data centers, the network must route traffic outside the security perimeter. The correct solutions involve using GRE tunnels with VRFs or MPLS L2VPNs to bypass the firewall.
Many candidates choose options that keep traffic within the same zone or through the firewall, such as L3VPN without tunneling, failing to realize these still traverse the inspected path.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct The core requirement is to stop the firewall from inspecting traffic between the two data centers. This implies the traffic must physically or logically bypass the firewall's inspection engine. Option A (GRE over VRF) creates a tunnel that encapsulates the traffic, effectively making it 'transit' traffic rather than local intrazone traffic, thus avoiding deep packet inspection if the firewall is not configured to terminate the tunnel. Option B (MPLS L2VPN) extends the Layer 2 domain directly between routers/switches via the provider cloud, completely bypassing the customer-edge firewalls for this specific traffic flow.
Why the Other Options Are Wrong Option C is incorrect because enabling MPLS requires a signaling protocol like LDP or RSVP-TE; you cannot simply 'enable MPLS' through a GRE tunnel as GRE does not carry MPLS labels natively without additional encapsulation complexities not implied here. Option D is less optimal than B for router-to-router interconnects described in typical WAN designs, and extending switches might introduce spanning tree issues across sites. Option E (L3VPN) typically routes traffic through the provider edge, which often connects back into the customer's routing infrastructure where firewalls reside, potentially still subjecting it to policy unless specifically tunneled.
Community Comment Notes The community discussion highlights the scalability aspect due to increasing zones. As JCGO noted, "So scalable solution needed... L2 per VRF or GRE per VRF will not scale," suggesting a preference for transport mechanisms that handle multiple VRFs/VLANs efficiently. Weltbuerger and sandccie support BE, arguing that MPLS L2VPN is more scalable for extending multiple VLANs compared to individual GRE tunnels per VRF.
Official Reference
Exam Strategy
When asked to avoid firewall inspection, look for solutions that create a direct transport path (tunnel or L2 extension) that does not terminate at the firewall. GRE tunnels are a classic way to hide payload content from intermediate devices.
Frequently Asked Questions
Why doesn't L3VPN avoid firewall inspection?
L3VPN routes traffic through provider edges, which often feed back into customer sites where firewalls sit. Unless tunneled, it may still be inspected.
Is GRE better than L2VPN for scaling?
L2VPN (like EVPN/VPLS) scales better for many VLANs. GRE requires a separate tunnel per VRF, which becomes complex to manage at scale.