CCNP Infrastructure Practice Question
A network engineer is implementing VXLAN with a Layer 2 gateway on a Cisco Nexus 9000 series switch. The design uses a distributed anycast gateway to provide optimal forwarding for hosts in the same subnet across different leaf switches. The engineer needs to ensure that all leaf switches use the same virtual MAC address for the gateway. Which feature must be configured to achieve this?
⚠ Common exam trap
The trap here is assuming that traditional first-hop redundancy protocols like HSRP, VRRP, or GLBP can provide a distributed anycast gateway, when they actually elect a single active gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Anycast gateway
The anycast gateway feature in Cisco VXLAN allows all leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This provides active-active gateway functionality, ensuring that hosts always use the optimal path and avoiding traffic tromboning. Configuring the same virtual MAC on all leaf switches is part of the anycast gateway configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
HSRP
Why it's wrong here
HSRP is a first-hop redundancy protocol that elects a single active gateway and one or more standby gateways. It does not allow multiple switches to simultaneously act as the gateway with the same MAC; only the active switch forwards. HSRP is not suitable for distributed anycast gateway in VXLAN.
- ✗
VRRP
Why it's wrong here
VRRP is similar to HSRP in that it elects a master and backup routers. It does not provide active-active gateway functionality across multiple leaf switches with a shared virtual MAC. VRRP would cause suboptimal routing because only one switch forwards traffic for the virtual IP.
- ✓
Anycast gateway
Why this is correct
The anycast gateway feature allows multiple leaf switches to share the same virtual IP and MAC address for a subnet's default gateway. This enables hosts to use a consistent gateway regardless of their location, and ensures optimal forwarding without traffic tromboning. Configuring the same virtual MAC on all leaf switches achieves the requirement.
- ✗
GLBP
Why it's wrong here
GLBP provides load balancing across multiple gateways, but each gateway has a different virtual MAC address. It does not allow all leaf switches to use the same virtual MAC for a subnet. GLBP is not used for distributed anycast gateway in VXLAN designs.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.