A company uses Cisco NFVIS to host a virtual ASA (vASA) and a virtual router (vRouter). The engineer notices that the vASA cannot communicate with the vRouter even though both are on the same NFVIS host. The vASA is connected to a bridge network, and the vRouter is connected to a different bridge. What should the engineer do to enable communication between the two VNFs?
Correct. In NFVIS, you can create a Linux bridge that acts as a virtual Layer 2 switch. Attaching both VNFs' vNICs to the same bridge places them in the same broadcast domain, allowing direct communication via MAC learning and forwarding. Alternatively, if the VNFs reside on different bridges (separate Layer 2 domains), you can use a virtual router—either a VNF configured for routing or NFVIS's own virtual switch—to route packets between those bridges. This is the standard method for inter-VNF connectivity on a single NFVIS host.
Why this answer
In NFVIS, VNFs attached to different bridge networks are isolated at Layer 2. To enable communication between them, you must either create a new bridge that connects both VNFs or use a virtual switch (e.g., a Linux bridge with routing enabled) to forward traffic between the two bridges. This allows the VNFs to share a common Layer 2 domain or have a routed path through the hypervisor.
Exam trap
Cisco often tests the misconception that VLAN tagging alone can connect VNFs across different bridges, but VLANs only segment traffic within a single bridge and do not create connectivity between separate bridges.
How to eliminate wrong answers
Option A is wrong because physically cabling ports on the NFVIS host would create a loop or require external hardware, and NFVIS does not support direct physical loopback connections for internal VNF-to-VNF traffic. Option C is wrong because VLAN tagging alone does not bridge separate bridge networks; both VNFs would need to be on the same bridge with matching VLANs for Layer 2 connectivity. Option D is wrong because static routes only work if there is already a Layer 3 path between the VNFs; with different bridges, there is no connectivity at Layer 2 or Layer 3 without an intermediate router or bridge.