Which of the following statements describes the function or operation of the integrated gateway-based data center interconnect solution?
All the data center leaf routers must be reachable over the WAN network.
The route reflectors in the different data centers must be able to reach each other.
The VXLAN tunnels are required between the leaf routers in the different data centers.
The data center gateway and the WAN PE functions are performed on a single router.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In an integrated gateway-based DCI design, the same physical or logical router performs both the data center gateway role and the WAN PE role. This is why option D is correct. The device terminates or participates in the data center-side EVPN service and also handles the WAN-side VPN transport, including route translation or re-advertisement where needed. This approach avoids exposing every data center leaf router to the WAN and avoids requiring route reflector reachability between data centers. It also avoids building VXLAN tunnels directly between all leaf routers in separate data centers. Those characteristics belong to gateway-less DCI, where the EVPN overlay stretches more directly across the WAN and the WAN must carry the underlay or overlay reachability required by the data center leaves. Integrated gateway design is more controlled: the gateway is the interworking point, which makes it suitable when the provider or operator wants a strong service boundary and centralized DCI policy enforcement. Reference: integrated gateway-based DCI, single-router gateway/WAN PE function, EVPN/VPN interworking.
================
Consider the exhibit.

Based upon the information in the screen captures, which of the following statements is FALSE?
Leaf-1 will not generate any EVPN route-type 5 updates for IP-VRF-100.
The IRB interface will snoop all ARP and GARP messages received on IRB sub-interface 100.100.
Leaf-1 will advertise EVPN route-type 2 updates with host IP and MAC information for MAC-VRF100.
The ARP cache for ip-vrf 100 is only required to contain host prefixes for the local subnets.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
The exhibit describes an EVPN IRB environment where MAC-VRF100 and IP-VRF-100 exchange host reachability through local learning and EVPN advertisements. Leaf-1 can advertise EVPN route type 2 updates containing host MAC/IP information for MAC-VRF100. This is the normal mechanism used to distribute endpoint bindings learned from local hosts. If IP-VRF-100 is not configured for prefix advertisement, Leaf-1 will not generate EVPN route type 5 updates for that IP-VRF, so option A is consistent. The ARP cache in the IP-VRF is normally required for local subnet host resolution; remote host reachability can be learned through EVPN rather than requiring every remote ARP entry to be learned by local data-plane ARP. Option B is false because ARP/GARP snooping is not performed by the IRB interface in the manner stated. ARP/GARP learning for proxy ARP and MAC/IP advertisement is associated with the MAC-VRF bridge-domain behavior and the local access side, not with the IRB subinterface indiscriminately snooping all ARP/GARP messages as described. Reference: EVPN IRB operation, RT-2 host MAC/IP advertisement, RT-5 behavior, ARP/GARP learning scope.
================
Which of the following statements about the decoupled gateway-based data center interconnect solution is FALSE?
VLAN tags are used to identify traffic between the data center border leaf and the WAN PE.
The EVPN services in the data center are interconnected to different VPN services in the WAN.
The separation between the border leaf and the WAN PE provides a clear demarcation for security and QoS.
The WAN PE maintains a peering session with the data center route-reflector for the exchange of updates.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In a decoupled gateway-based DCI design, the data center border leaf and the WAN PE are separate devices. Traffic between them can be identified using VLAN tags, allowing different data center EVPN services to be mapped to corresponding WAN VPN services. This architecture provides a clean operational boundary: the border leaf remains aligned with the data center EVPN/VXLAN fabric, while the WAN PE handles WAN VPN transport, QoS, security policy, and service interconnection. The separation gives a strong demarcation point for troubleshooting and administrative control. Option D is false because the WAN PE does not maintain an MP-BGP EVPN peering session with the data center route reflector. In the decoupled model, the route reflector remains part of the data center EVPN control plane, while the WAN PE exchanges routing or service information with the border leaf through the local handoff model. Direct WAN PE-to-data-center-RR peering would blur the separation that defines the decoupled design and would make the WAN PE part of the data center EVPN overlay control plane, which is not the intended architecture. Reference: decoupled gateway DCI, VLAN handoff, WAN VPN mapping, security/QoS demarcation, route-reflector separation.
================
Consider the exhibit.

All connected leaf routers have the same Ethernet segment configuration. The IP-VRF is configured properly and is operational.
Which of the following statements is FALSE?
This Ethernet segment is configured for Layer 3 multi-homing.
The EVI for the IP-VRF using this segment is 1000.
A LAG must be configured on the connected leaf routers and the host.
The redundancy mode for this Ethernet segment is all-active.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
The exhibit describes a Layer 3 multi-homing scenario where the Ethernet Segment is associated with an IP-VRF and the configuration references an EVI value of 1000. The segment is configured with all-active multi-homing, allowing multiple attached leaf routers to advertise reachability for the same external L3 next-hop or third-party prefix attachment. In this model, the Ethernet Segment represents the shared L3 attachment and is used by EVPN to associate remote prefix reachability with the multi-homed segment. The incorrect statement is that a LAG must be configured on the connected leaf routers and the host. That requirement is specific to many Layer 2 all-active host attachment designs, where the host commonly uses LACP toward multiple leaf routers and the leaf LAG subinterfaces are associated with the Ethernet Segment. In Layer 3 multi-homing, the attached device can be a router or VNF, and the EVPN ES association can be used for L3 prefix reachability without mandating that the host side be configured as a LAG. Reference: L3 EVPN multi-homing, EVI association, all-active Ethernet Segment behavior.
================
Which of the following GARP functions is FALSE?
A host sends a GARP to update its own IP/MAC mapping to the other hosts in the subnet.
All other hosts within the subnet will update their ARP tables.
The GARP is sent as a broadcast.
The other hosts in the subnet will acknowledge the receipt with a reply.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
A Gratuitous ARP is an ARP message a host sends to announce or refresh its own IP-to-MAC binding without waiting for another host to request it. In a traditional Ethernet subnet, the GARP is sent as a broadcast so that other hosts can update their ARP caches with the sender's current MAC address. This is useful after a host boots, changes NICs, moves to another attachment point, or takes over an IP address in a redundancy scenario. In EVPN environments, GARPs are also important because a leaf can snoop the ARP information and update local proxy ARP and EVPN MAC/IP state. Option D is false because recipients do not acknowledge a gratuitous ARP with a reply. GARP is an announcement mechanism, not a request/response transaction. If every receiving host acknowledged a broadcast GARP, the result would be unnecessary ARP traffic amplification. The correct behavior is passive update of ARP state by receiving systems and, in EVPN, potential control-plane propagation of the learned binding by the local PE. Reference: GARP behavior, proxy ARP learning, Layer 2 EVPN endpoint update procedures.
================
Which of the following statements about a L3 EVPN network using symmetric routing is FALSE?
Each participating PE must support the use of EVPN route-type 5.
Ingress and egress PEs perform MAC and IP forwarding.
A routed-VXLAN interface is required on a per IP-VRF basis.
Each MAC-VRF used in the L3 EVPN network must exist on each PE.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
Symmetric L3 EVPN routing uses an IP-VRF-based overlay model in which both ingress and egress PEs participate in routed forwarding. The ingress PE receives the frame from the local MAC-VRF, routes it into the IP-VRF, and sends it across the VXLAN routed interface. The egress PE receives the routed overlay packet, performs the corresponding IP-VRF lookup, and then forwards it into the locally attached destination MAC-VRF. Because the routed overlay is built per IP-VRF, a routed-VXLAN interface is required for that IP-VRF. EVPN route type 5 support is also required because RT-5 carries IP prefix reachability across the EVPN control plane. The false statement is option D. Symmetric routing specifically removes the requirement for every MAC-VRF to exist on every PE. A PE only needs the MAC-VRFs for locally attached subnets, plus the shared IP-VRF and routed overlay state. This is the major scaling advantage of symmetric routing compared with designs that require broad MAC-VRF instantiation across the fabric. Reference: symmetric L3 EVPN routing, routed VXLAN interface, RT-5 prefix reachability, MAC-VRF scaling.
================
Consider the exhibit.

The network is configured for interface-less symmetric routing with an ECMP of 4 enabled on all leaf routers.
Which of the following statements is FALSE?
Anycast gateway is an optional configuration on the Leaf1 and Leaf2 IRB interfaces.
The IRB interfaces on Leaf1 and Leaf2 must be configured to advertise learned local host-routes.
MAC-VRF100 on Leaf1 and Leaf2 must have BGP EVPN and BGP VPN configured.
IP-VRF1 on Leaf1, Leaf2 and Leaf3 must be configured with a VXLAN-routed interface.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In interface-less symmetric L3 EVPN routing, hosts in a subnet may be attached to different leaf routers, while inter-subnet forwarding is performed through the IP-VRF using VXLAN routed interfaces. The ingress and egress PEs both participate in L3 forwarding, and the routed VXLAN interface provides the per-IP-VRF overlay data-plane construct needed for symmetric routing. The IRB interfaces on the local MAC-VRFs must advertise learned local host routes so that remote PEs have the necessary host reachability information. The MAC-VRFs also need the appropriate EVPN control-plane configuration so host MAC/IP information can be exchanged, while the IP-VRF participates in L3 VPN-style route exchange for routed reachability. Option A is false because anycast gateway is not optional in this design for Leaf1 and Leaf2. Anycast gateway allows the same default-gateway IP and virtual MAC behavior to exist consistently on multiple leaves serving the same subnet. Without it, host default-gateway behavior would be inconsistent and traffic mobility across the fabric would break expected distributed gateway operation. Reference: interface-less symmetric routing, IRB, anycast gateway, routed VXLAN interface.
================
Which of the following statements about utilizing asymmetric routing in an L3 EVPN network is FALSE?
If a host interface's has two IP addresses, it must send out two separate EVPN route-type 2 updates for the MAC-VRF.
Each PE must have a full ARP table for all of the hosts in the L3 EVPN network.
All the MAC-VRFs connected to the L3 EVPN network must exist on each PE.
The ingress and egress PE routers will perform both MAC and IP forwarding.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
Asymmetric routing relies heavily on host MAC/IP information because the ingress PE performs routing into the destination subnet and then sends the frame across the overlay using the destination MAC-VRF/VNI. This means PEs require enough ARP and MAC/IP binding information to forward traffic toward remote hosts correctly. If a host has multiple IP addresses on the same interface, separate EVPN route type 2 advertisements may be needed to communicate each IP-to-MAC binding. The ingress and egress PEs participate in MAC and IP forwarding across the end-to-end service path, but the forwarding responsibilities differ by direction and stage. The false statement is option C. The statement says all MAC-VRFs connected to the L3 EVPN network must exist on each PE, but that is not the correct requirement in this question's verified answer set. In practical EVPN designs, the exact MAC-VRF placement depends on whether the service is implemented as asymmetric, symmetric, interface-less, or interface-ful routing. Here, the course answer marks the universal MAC-VRF requirement as false. Reference: asymmetric L3 EVPN routing, RT-2 MAC/IP advertisements, ARP and MAC forwarding behavior.
================
Consider the exhibit.

Which of the following statements about the operation of all-active multi-homing is FALSE?
Both Leaf1 and Leaf2 can forward BUM traffic to the host.
Leaf3 can load balance traffic between Leaf1 and Leaf2 when ECMP is enabled on the MAC-VRF.
The Ethernet segment on Leaf1 and Leaf2 is associated to lag 1.
The host can forward BUM traffic to either Leaf1 or Leaf2.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In an all-active Layer 2 EVPN multi-homing design, the host is normally dual-attached through a LAG to multiple leaf routers that share the same Ethernet Segment Identifier. Leaf1 and Leaf2 both participate in the Ethernet Segment and may receive traffic from the host. For BUM traffic sourced by the host, the host-side hashing can send frames toward either attached leaf. For BUM traffic sent from the EVPN overlay toward the multi-homed segment, DF election controls which PE forwards that replicated traffic toward the local Ethernet Segment to prevent duplicate delivery. The false statement is option B. A remote leaf such as Leaf3 does not simply enable ECMP on the MAC-VRF to load-balance traffic between Leaf1 and Leaf2. EVPN all-active forwarding uses Ethernet Segment discovery, Ethernet A-D routes, aliasing, and split-horizon procedures to determine valid next-hops and prevent loops. ECMP alone is an underlay or routing-table behavior; it is not the MAC-VRF mechanism that authorizes multi-homed L2 forwarding across an Ethernet Segment. Reference: all-active L2 EVPN multi-homing, Ethernet Segment association, DF election, aliasing.
================
Which of the following statements about MAC mobility is TRUE?
The original PE advertises the locally learned MAC with the sequence number set to a maximum value.
A PE advertising a local MAC that was previously learned through EVPN, will decrement the sequence number in its update.
The originating PE generates a withdraw message after the same locally learned MAC has aged out.
The originating PE and the destination PE must synchronize their MAC tables.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
MAC mobility is the EVPN mechanism used when a host MAC moves from one PE to another. The control plane uses a MAC Mobility extended community and sequence number behavior to determine the most recent valid location for the MAC. When a PE locally learns a MAC that was previously learned through EVPN, it advertises the MAC with an incremented sequence number, allowing remote PEs to prefer the newer location. Therefore, option B is wrong because the sequence number is not decremented. Option A is also wrong because the original PE does not advertise the locally learned MAC with a maximum sequence value as a normal mobility procedure. Option D is inaccurate because PEs do not need direct MAC table synchronization; they rely on EVPN control-plane advertisements and withdrawals. The true statement is option C: the originating PE generates a withdraw message after the same locally learned MAC ages out. This withdrawal removes stale reachability from remote PEs and prevents continued forwarding toward a PE that no longer has the host locally attached. Reference: EVPN MAC mobility, sequence-number handling, MAC route withdrawal after aging.
================
Consider the exhibit.

Which of the following statements about the configuration and operation of this setup is FALSE?
The Ethernet segment ES-1 is configured as single active.
The ports that connect to the host are associated to ES-1.
All traffic to and from the host will flow through Leaf1.
The host will be required to be configured with a LAG.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
This setup represents single-active Layer 2 EVPN multi-homing. In single-active mode, the Ethernet Segment is configured so that only one PE acts as the active forwarding node for a given service, while the other remains standby. The ports connecting to the host are associated with ES-1 so the EVPN control plane can perform Ethernet Segment discovery, DF election, and standby behavior. If Leaf1 is the active/DF node for the service, all traffic to and from the host flows through Leaf1 until a failure or DF transition occurs. Option D is false because a host LAG is not required for this single-active topology. A LAG is typically required for all-active L2 multi-homing, where the host must treat multiple physical links toward different leaf routers as one logical bundle. In single-active operation, the host can be connected through separate physical links or active/standby access behavior without requiring LACP bundling. The EVPN PEs enforce the active path selection through DF and ES state rather than relying on host-side LAG hashing. Reference: single-active EVPN multi-homing, Ethernet Segment port association, DF-controlled active forwarding.
================
When configuring the EVPN MP-BGP route reflector sessions between the leaf and spine routers, which of the following statements is TRUE?
The local-AS number configured within the BGP group will override the AS number configured directly under the BGP protocol.
The cluster-id that uniquely identifies this route reflector session is configured on the route reflector and participating clients.
When redundant route reflectors are deployed, one route reflector will be the primary while the other one will assume a backup role.
Route reflectors can be used instead of a full mesh of eBGP sessions between the leaf and spine routers.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In SR Linux BGP configuration, parameters defined at a more specific hierarchy level can override broader protocol-level settings. Therefore, if a `local-as` value is configured within the BGP group used for EVPN MP-BGP route-reflector sessions, that value overrides the AS number configured directly under the BGP protocol for that group's sessions. Option A is correct. Option B is false because the cluster ID is configured on the route reflector, not on every participating client. The cluster ID identifies the RR cluster and helps prevent route-reflection loops. Option C is false because redundant route reflectors normally operate in parallel rather than as strict primary/backup devices; clients can peer with both for resilience. Option D is misleading because EVPN route reflectors are used to avoid a full mesh of overlay MP-BGP EVPN sessions between leaves, not to replace ordinary underlay eBGP leaf-spine routing sessions. In a clean fabric design, the underlay provides IP reachability, while the EVPN overlay uses MP-BGP sessions, often via route reflectors, to distribute tenant reachability. Reference: SR Linux BGP hierarchy, EVPN route reflector sessions, local-AS override, cluster ID behavior.
================
Consider the exhibit.

Which of the following statements about the proxy ARP entry for the neighbor IP 192.168.100.1 is FALSE?
The state is pending because this MAC address was originally associated with a different IP address.
The traffic will be forwarded to a blackhole if the state changes to duplicate.
The MAC address will be changed to 00:00:00:00:DE:AD if the state changes to duplicate.
All traffic destined to 192.168.100.1 will be discarded for 9 minutes if the state changes to duplicate.
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
Proxy ARP in a Layer 2 EVPN service allows the leaf to answer ARP requests locally using learned IP/MAC bindings, reducing broadcast flooding across the overlay. SR Linux can also monitor IP duplication and MAC/IP inconsistencies in the proxy ARP table. A pending state indicates that the system has detected suspicious or conflicting information and is monitoring the binding before declaring it duplicate. If the entry becomes duplicate, SR Linux can use a blackhole behavior to prevent forwarding traffic toward a conflicted endpoint, and a special discard MAC such as 00:00:00:00:DE:AD can be associated with the duplicate entry. Option D is false because it incorrectly states that all traffic destined to 192.168.100.1 will be discarded for exactly 9 minutes. The exhibit references monitoring and hold-down behavior, but the answer key rejects the fixed “9 minutes” traffic-discard statement. The key concept is that duplicate handling protects the EVPN service from unstable or conflicting IP/MAC bindings, but the specific discard duration in option D is not correct. Reference: proxy ARP, IP duplication monitoring, duplicate-state blackhole behavior.
================
TESTED 30 Sep 2026
