A network engineer must allow secure access to the Cisco ACI out-of-band (OOB) management only from external subnets 10.0.0.0/24 and 192.168.20.0/25. Which configuration set accomplishes this goal?
A.
Create a L3Out in the MGMT tenant in OOB VRF. Set External Management Network Instance Profile as a consumer of the OOB contract. Create an External EPG with two subnet entries with the external subnets.
B.
Create a PBR service graph in the MGMT tenant. Create a management Profile with the required OOB EPG. Redirect all traffic going into ACI management to the external firewall. Create two subnet entries under the OOB Bridge domain with the required subnets.
C.
Create an EPG and BD in the MGMT tenant in OOB VRF. Set OOB VRF to provide the contract. Set a new EPG to consume the OOB contract.
D.
Create an OOB contract that allows the required ports. Provide the contract from the OOB EPG. Consume the contract by the OOB External Management Network Instance Profile. Create two subnet entries in the External Management Network Profile with the required subnets.
D -
Step 1 – Providing the contract
Tenant > Tenant mgmt > Node Management EPGs > Out-of-Band EPG default
• Under the “Provided Out-of-Band Contracts” in the policy window, provide the appropriate contract. (This
could be a the default/common contract or a specific contract you have created and modified). Click Submit.
Tenant > Tenant mgmt > Node Management EPGs > Out-of-Band EPG default
Step 2 – Consuming the contract
Tenant > Tenant mgmt > External Management Network Instance Profiles > YourInstanceProfile
• Consume the same contract that you provided in the previous step.
• Enter the subnets that are allowed to have access to the APIC. (0.0.0.0/0 will permit all).
https://www.cisco.com/c/dam/en/us/solutions/collateral/data-center-virtualization/application-centric-infrastructure/aci-guide-configuring-out-of-band-access-for-your-fabric.pdf
This section is not available anymore. Please use the main Exam Page.300-620 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Mr_Certifiable
5Â months, 1Â week agoNarbledeath
6Â months, 3Â weeks ago