In an EVPN-VXLAN deployment, what is the significance of route distinguishers and route targets?
Correct Answer: D
Question 62
You are planning to deploy a fabric in your large campus with 10,000+ users. You will have both Layer 2 and Layer 3 devices that connect to your access switches. In this scenario, which campus architecture should you use?
Correct Answer: D
According to Juniper's Validated Designs (JVD) for campus fabrics, the Campus Fabric IP Clos (often referred to as a 5-stage Clos) is the architecture specifically engineered for high-scale environments supporting 10,000+ users. This design is characterized by extending the EVPN control plane and VXLAN data plane all the way to the access layer. By terminating VXLAN tunnels at the access switch-functioning as a Virtual Tunnel Endpoint (VTEP)-the network can seamlessly support both Layer 2 and Layer 3 devices directly at the edge of the fabric. The primary driver for choosing IP Clos in large-scale deployments is its superior scalability. In this model, the core switches are shielded from the massive table sizes required to learn thousands of individual endpoint MAC and IP addresses. Instead, core devices only need to maintain reachability to the loopback addresses of the access layer switches. This reduction in the "flood and learn" pressure on the core is critical as the number of endpoints grows, ensuring that the core can scale far into the future with predictable growth. Additionally, the IP Clos architecture provides the most flexible environment for microsegmentation using Group-Based Policies (GBP) and macrosegmentation using Virtual Routing and Forwarding (VRF) instances. Since routing occurs at the access device, "east-west" traffic between local endpoints remains efficient and does not need to traverse the distribution or core tiers. While EVPN Multihoming and Core- Distribution (CRB/ERB) models are effective for smaller sites or brownfield environments where access switches are legacy Layer 2-only devices, only the IP Clos architecture provides the end-to-end VXLAN capability required for high-density, future-proof campus fabrics.
Question 63
A company has a Mist campus fabric with a single VRF and must configure group-based policy (GBP) tags to isolate different types of endpoints. What would be an appropriate solution for this scenario?
Correct Answer: B
Juniper Mist AI for Wired uses group-based policy (GBP) to enforce segmentation within a single VRF, without requiring separate VRFs per user group. GBP tags classify endpoints logically (e.g., employees, guests, IoT devices) and enforce security rules across the EVPN-VXLAN fabric. "Group-Based Policy (GBP) provides scalable segmentation by assigning tags to endpoints based on attributes such as user type, role, or device type. These GBP tags are then used in policies to control communication between groups." Option A is inefficient: assigning unique tags per endpoint is not scalable. Option C is incorrect: GBP is identity-based segmentation, not location-based. Option D is incorrect: assigning a single tag defeats the purpose of segmentation. Option B is correct: the best practice is to assign GBP tags based on endpoint type (e.g., servers, staff, IoT, guests), which then drives policy enforcement. References: Juniper Mist AI for Wired - Group-Based Policy (GBP) Configuration Guide Juniper Validated Design - GBP with EVPN-VXLAN in Campus Fabrics
Question 64
How do Client Insights assist in Wired Assurance Operations?
Correct Answer: A
Question 65
What are Service Level Expectations (SLEs) used for in Wired Assurance Management?