Question 1
A financial institution is implementing a multi-VRF environment on their ArubaOS-CX core switches to segment traffic between corporate, trading, and guest networks. A network architect needs to ensure that specific high-priority trading data from the trading VRF can be routed to a shared monitoring service located in the corporate VRF, without leaking all routes between the VRFs. Which routing feature is the most precise and secure method to achieve this specific inter-VRF communication?
Answer and explanation
Correct answer: C
The most scalable, secure, and precise method for controlled inter-VRF routing on ArubaOS-CX switches is using Multi-Protocol BGP (MP-BGP) with route targets (RTs). By configuring specific RTs for export on one VRF and for import on another, an administrator can selectively leak only the required routes (e.g., the monitoring service prefix) without merging the entire routing tables. Static routes are less dynamic, and PBR is more for path selection than inter-VRF routing. Merging VRFs into a global table is insecure and defeats the purpose of segmentation.