NVIDIA AI Infrastructure NCP-AII Question # 3 Topic 1 Discussion
NCP-AII Exam Topic 1 Question 3 Discussion:
Question #: 3
Topic #: 1
An engineer is tasked with configuring Out-of-Band management for a DGX BasePOD deployment. Which network design will best ensure secure and reliable Out-of-Band management operations?
A.
Use a single VLAN for both Out-of-Band management and compute fabric to simplify network design.
B.
Configure Out-of-Band management interfaces to be accessible from any subnet within the data center for maximum flexibility.
C.
Connect Out-of-Band management ports to the same switch as user traffic for easier troubleshooting.
D.
Place all BMC and management interfaces on an isolated Out-of-Band network with access restricted by firewall rules.
The best design is to place all BMC and management interfaces on an isolated Out-of-Band network with access restricted by firewall rules. Out-of-Band management provides administrative access for hardware monitoring, remote console, power operations, firmware maintenance, and recovery actions even when the host operating system or production network is unavailable. Because BMC interfaces are powerful administrative control points, they should not share the same network as user traffic or the high-performance compute fabric. NVIDIA DGX guidance recommends restricting IPMI or BMC ports to an isolated, dedicated management network, using a separate firewalled subnet, or using a separate VLAN for BMC traffic when a dedicated network is unavailable. Allowing access from any subnet increases the attack surface and weakens operational security. Sharing the same switch or VLAN as production traffic can also expose management interfaces to congestion or unauthorized access. A dedicated OOB network improves security, reliability, and serviceability for DGX BasePOD operations.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit