A financial services company is deploying a new data center using Huawei's CloudFabric solution with a BGP EVPN VXLAN fabric. The design requires that tenant VRFs be extended across multiple PoDs (Points of Delivery) for active-active services. To achieve this, a network architect plans to use EVPN Type-5 routes to advertise external prefixes into the fabric. Which component is responsible for originating these Type-5 routes and leaking them between tenant VRFs and the underlay routing table?
Answer and explanation
Correct answer: C
In a BGP EVPN VXLAN fabric, border leaf switches function as the gateways between the VXLAN overlay network and external networks. They are responsible for route leaking between tenant VRFs and the public or underlay network. When advertising external prefixes (like those learned from a PE router) into the EVPN fabric, the border leaf originates EVPN Type-5 (IP Prefix) routes. This allows workloads within the fabric to communicate with external services.
Question 2
Multiple answers
During the deployment of an intelligent lossless network for a new AI training cluster, a network engineer observes that while Priority Flow Control (PFC) is enabled for the RoCEv2 traffic class, congestion is still causing high latency. Further investigation reveals that Explicit Congestion Notification (ECN) is not being correctly processed. Which two components must be correctly configured to work in tandem for a Data Center Quantized Congestion Notification (DCQCN) algorithm to function effectively? (Select TWO)
Answer and explanation
Correct answers: A, B
DCQCN is a proactive congestion control mechanism that relies on two key actions. First, the switch detects incipient congestion (e.g., buffer queue exceeding a threshold) and marks the ECN bits on passing packets. Second, the destination host's NIC receives these marked packets and sends a Congestion Notification Packet (CNP) back to the original sender, instructing it to reduce its transmission rate. PFC is a reactive mechanism (pausing traffic) that works alongside DCQCN.
Question 3
A cloud service provider is using Huawei CloudFabric to offer multi-tenant services on an OpenStack platform. A new tenant requires a three-tier application (Web, App, DB) with strict security policies enforced by a virtual firewall. The network administrator needs to automate the deployment of this service chain. Which iMaster NCE-Fabric feature should be used to define the traffic path and ensure that all inter-tier traffic is steered through the virtual firewall service function?
Answer and explanation
Correct answer: B
Service Function Chaining (SFC) is the specific technology designed for steering traffic through an ordered sequence of service functions, such as firewalls, load balancers, or intrusion detection systems. Within iMaster NCE-Fabric, an administrator would define a service chain that specifies the virtual firewall as a required hop for traffic flowing between the Web, App, and DB tiers (EPGs). This ensures security policies are applied without complex manual routing.
Question 4
An architect is designing the underlay network for a new spine-leaf data center fabric that will host over 2000 servers. The primary requirements are fast convergence, scalability, and operational simplicity. The fabric will use BGP EVPN for the overlay. Which underlay routing protocol would be the best practice for this scenario?
Answer and explanation
Correct answer: B
Using eBGP for the underlay is a modern best practice for large-scale spine-leaf fabrics. Assigning a unique private ASN to each leaf switch (or rack) and another to the spine layer creates a simple, highly scalable, and loop-free routing domain. This design avoids the complexities of IGP flooding, simplifies troubleshooting, and aligns well with the BGP-based EVPN overlay. It offers excellent ECMP support for load balancing across the fabric.
Question 5
A network operations team is using iMaster NCE-Fabric for automated O&M. They receive an alert from FabricInsight indicating high network latency for a specific application. To perform root cause analysis, the team needs to visualize the end-to-end path of the application's traffic flow, including all physical and virtual nodes. Which FabricInsight feature provides this capability?
Answer and explanation
Correct answer: B
FabricInsight's Proactive Path Detection feature allows operators to define an application or flow (based on source/destination IP, port, etc.) and then uses telemetry data to trace and visualize its complete path through the network. This includes the source VM, physical leaf, spine, destination leaf, and destination VM. It highlights latency and packet drop statistics at each hop, enabling rapid identification of performance bottlenecks.
Question 6
True or False: In a Huawei CloudFabric solution, microsegmentation is achieved by defining Endpoint Groups (EPGs) and then applying contracts between them. A contract is required even for EPGs within the same tenant VRF to allow traffic.
Answer and explanation
Correct answer: A
This is true. The microsegmentation model in solutions like Huawei CloudFabric (similar to Cisco ACI) operates on a zero-trust, whitelist principle. By default, all traffic between different EPGs is denied, even if they belong to the same VRF or subnet. A contract, which defines the allowed protocols and ports, must be explicitly configured and applied between the source and destination EPGs to permit communication.
Question 7
Multiple answers
A large e-commerce platform runs its application on a Kubernetes cluster integrated with a Huawei CloudFabric data center network. To expose their services to the internet, they use the Kubernetes LoadBalancer service type. Which two of the following components work together to automatically provision an external IP and configure the necessary network policies on the fabric? (Select TWO)
Answer and explanation
Correct answers: B, C
In a tightly integrated environment, when a developer creates a LoadBalancer service in Kubernetes, the API request is intercepted. The Huawei CNI plugin communicates this request to the iMaster NCE-Fabric controller. NCE-Fabric then orchestrates the allocation of an external IP address (from a predefined pool) and programs the border leaf switches with the necessary NAT and load balancing rules to direct external traffic to the correct service pods.
Question 8
Case Study:
A retail company is migrating its on-premises infrastructure to a new data center built with the Huawei CloudFabric solution. The company has two primary data centers, DC1 (Primary) and DC2 (Disaster Recovery), located in different cities. The business requires active-active access to applications hosted in both data centers and seamless VM mobility for maintenance and disaster avoidance. The infrastructure consists of a VXLAN EVPN fabric in each DC, managed by iMaster NCE-Fabric.
The network team is responsible for designing the Data Center Interconnect (DCI) solution. A key requirement is that a VM's IP address and MAC address must remain the same when it is moved from DC1 to DC2. Furthermore, traffic from a VM in DC1 destined for a VM in DC2 should take the most optimal path without hairpinning through a centralized gateway.
To meet these requirements, the network team needs to extend the L2 and L3 domains across both data centers. They are considering different VXLAN gateway deployment models for the DCI.
Which DCI design using BGP EVPN best fulfills all the stated requirements for seamless mobility and optimal traffic forwarding?
Answer and explanation
Correct answer: B
This design is the optimal solution. Deploying distributed anycast gateways on all VTEPs (leaf switches) in both data centers allows VMs to use a consistent gateway IP regardless of their location. Extending the EVPN control plane between the DCs allows for the exchange of L2 (MAC/IP) and L3 (IP Prefix) reachability information. This enables seamless L2 extension for VM mobility and ensures that inter-DC traffic is routed optimally without trombone effects. EVPN multihoming on the DCI links provides redundancy and load balancing.
Question 9
A network architect is in the capacity planning phase for a new data center. The design uses a spine-leaf topology. The leaf switches have 48x25GE server-facing ports and 8x100GE uplink ports. To avoid performance bottlenecks, the architect needs to determine the oversubscription ratio from the leaf switches to the spine switches. What is the correct oversubscription ratio for this leaf switch configuration?
Answer and explanation
Correct answer: B
The oversubscription ratio is calculated by dividing the total bandwidth of the server-facing ports (downlinks) by the total bandwidth of the uplink ports. Total Downlink Bandwidth = 48 ports * 25 Gbps = 1200 Gbps. Total Uplink Bandwidth = 8 ports * 100 Gbps = 800 Gbps. Ratio = Downlink / Uplink = 1200 / 800 = 1.5. Therefore, the oversubscription ratio is 1.5:1.
Question 10
A DevOps engineer is attempting to automate the creation of a new tenant VRF and associated subnets in a Huawei CloudFabric environment using RESTful APIs provided by iMaster NCE-Fabric. The engineer sends a POST request to the correct API endpoint but receives a 401 Unauthorized error. What is the most likely cause of this issue?
Answer and explanation
Correct answer: C
The HTTP status code 401 Unauthorized specifically indicates that the request lacks valid authentication credentials. Before making functional API calls to iMaster NCE-Fabric, a client must first authenticate (typically with a username/password) to a login endpoint to obtain a temporary access token. This token must then be included in the header (e.g., X-Auth-Token) of all subsequent requests. A missing or expired token will result in a 401 error.