In Huawei's CloudFabric solution, tenants are performing VPC interconnection service orchestration
A.
When the virtual firewalls of two VPCs are distributed on two different physical firewalls, and traffic passes through the firewalls on both sides, and the two physical firewalls are connected to different service leaves, you need to create two different VRFs
B.
When two VPCs have their own virtual firewalls and traffic crosses the firewalls, and the service leaves of the two WCs are the same, and if they share a physical firewall, you need to create two different VRFs
C.
In all VPC interworking scenarios, if a meso-VRF is used, the VPC inter-communication will share a single interworking VRF, and the controller will not create two different interworking VRFs
D.
When the virtual firewalls of two VPCs are distributed on two different physical firewalls, and traffic passes through the firewalls on both sides, and two physical firewalls are connected to the same service leaf, two different VRFs need to be created
Analysis: Option B is incorrect, if the same physical firewall and ServiceLeaf are shared, only one VRF is required to communicate between VPCs. Option C and option D are wrong, depending on the scene, if two walls are connected to their own physical leaves, two interworking VRFs are requiredIf two walls are connected to the same physical leaf, only one interworking VRF is required to communicate between VPCs. Option A is correct. Bilateral FW and FW in the same device group: The two VPCs that access each other have their own virtual firewalls, traffic passes through the firewalls, and the service leaves of the two VPCs The virtual firewalls of two VPCs that access each other are distributed on two different physical firewalls, and the traffic is crossed by the firewall on both sides, and the two physical firewalls are connected to different firewalls Service Leaf。 Bilateral FW and Service Leaf in the same device group: The virtual firewalls of two VPCs that access each other are distributed on two different physical firewalls, and traffic is bilaterally passed through the firewall, and the two physical firewalls are connected to the same Service Leaf 。
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit