Q35Automation
The VMM domain is integrated between Cisco APICs and vCenter by using a distributed vSwitch. Traffic must be blocked between a subset of endpoints in an EPG, selected according to specific VM attributes, and the remaining VMs in that EPG. Which set of actions blocks this traffic?
← → navigate · a answer
Community votes
Discussion · 12
C 6
Selected Answer: C
C. 1. Set Allow Microsegmentation under the EPG VMM Domain Association to "True" 2. Set Intra-EPG Isolation to "Enforced" for the EPG 3. Set Intra-EPG Isolation to "Enforced" for the uSeg EPG.
Setting "Allow Microsegmentation" to "True" allows uSeg EPGs to be created. Setting "Intra-EPG Isolation" to "Enforced" for the EPG and uSeg EPG lets microsegmentation be enforced between the endpoints based on specific VM attributes. This blocks traffic between the subset of endpoints and the rest of the VMs in that EPG.
5
c is the correct one
4
I think it's D. The Intra EPG Isolation option is left Unenforced here.
https://aci-lab.ciscolive.com/lab/pod4/segmentation/mseg
D 4
Selected Answer: D
Intra-EPG Isolation Enforced = the main EPG can isolate within itself.
uSeg EPG Enforced = full isolation from each other and groups
uSeg EPG Unenforced = controlled isolation can communicate with each other based on policies
The request is to block traffic between a subset of endpoints in an EPG, not to fully isolate devices in an EPG
A 3
Selected Answer: A
there is no requirement to block traffic between EPs in same EPG or same useg EPG
A 3
Selected Answer: A
I would go with A too, intra-EPG isolation is not required, the question is asking for blocking traffic between uSeg EPG and the EPG.
3
I meant uSeg Intra-EPG Isolation is left Unenforced.
Base EPG Intra-EPG Isolation is Enforced.
D 3
Selected Answer: D
I agree with saju777. Check his reference, there is a config example:
enforcement for intra-epg isolation to on, no need for additional enforcement cause its a standard EPG no useg EPG
A 3
Selected Answer: A
The goal here is to block traffic between VMM attribute based EP and the rest EP in same EPG. We do not need to block traffic within the VMM based attribute EP group and the normal EP group. So we don't need to set the Intra-EPG isolation to enforce in the base EPG and the uEPG.
A 2
Selected Answer: A
Agreed, it should be A
C 1
Selected Answer: C
Cant be A, traffic must be denied between vm intra-epg
A 1
Selected Answer: A
The answer is A, based on the wording of the question. You want to block traffic between a subset of endpoints in an EPG, not between all endpoints in the EPG.