A Nutanix AHV administrator needs to keep Finance and Production VM traffic in separate broadcast domains. The administrator asks whether creating another bridge is equivalent to assigning another VLAN. Which action provides VLAN segmentation instead of merely creating another bridge domain?
Select an answer to reveal the explanation.
Short Explanation
Think of a bridge like the switch fabric under your feet, and a VLAN like colored tape on the wire. You can run several VLANs through one bridge, but the VLAN ID is what keeps broadcast domains apart. If you just add another bridge without tags, you're building more switch domains, not doing VLAN segmentation.
Full Explanation
In AHV, a bridge is the virtual switching domain that connects VM NICs, the host, and uplink physical NICs. It behaves like a layer 2 switch: frames are forwarded between ports in that bridge. A VLAN ID is an Ethernet tag that tells the bridge and physical switches which broadcast domain a frame belongs to. Segmentation comes from placing VM NICs in different VLAN IDs, because broadcasts and unknown unicast traffic are kept within each tagged domain, while one bridge can carry multiple VLANs. Creating another bridge without VLAN tags changes the local switching domain, but if its uplink joins the same physical VLAN, it does not provide tag-based isolation. Using different IP subnets on the same bridge and VLAN changes layer 3 addressing, not the layer 2 broadcast domain, so VMs can still be in the same VLAN. Adding a second physical NIC or bond member improves bandwidth or failover, but bond members do not create separate VLANs unless the traffic is tagged and the physical switch permits those VLANs. Exam caveat: Do not equate a bridge, a subnet, or a bond with a VLAN; the VLAN ID is the layer 2 isolation point. Operational check: Confirm the VM NIC network has the intended VLAN ID and that the corresponding uplink bridge carries that VLAN on the physical switch.