An administrator is preparing AHV nodes and must keep IPMI/BMC access separate from workload data traffic. Which action creates true out-of-band management isolation?
Select an answer to reveal the explanation.
Short Explanation
Think of IPMI like the master key to the server room: you don't want it on the same busy hallway as production traffic. Put the management NIC on its own VLAN/VRF outside the AHV data bridge. If you just add Flow rules or tag VLANs on the same bond, you're still sharing the hallway.
Full Explanation
Out-of-band management isolation means the Baseboard Management Controller/IPMI path does not share the AHV data plane used by VMs, storage, or CVM traffic. In practice, each node's IPMI/BMC NIC is connected to a physically separate switch network or placed in a dedicated management VLAN/VRF that is routed only by management infrastructure. This prevents workload traffic, misconfiguration, or saturation on the AHV bridge from affecting console access, power control, or sensor monitoring. Flow network security rules can restrict traffic but do not create separation when the management path shares the same bridge or physical NIC; they are enforcement on a shared path. Native VLANs on a bond still traverse the same aggregation and failure domain, so they separate broadcast domains but not out-of-band availability. Routing IPMI through the CVM or cluster management network reuses the same software and network stack, coupling management availability to AHV/CVM health and defeating the purpose of out-of-band control. Exam caveat: choose isolation when the stem asks for out-of-band management; filtering or VLAN tagging alone may not satisfy it. Operational check: confirm the IPMI NIC has an address only on the management VLAN/VRF and that AHV data VLANs, bonds, and bridges do not carry or route that subnet.