nerdexam
Cisco

300-415 · Question #171

An enterprise needs DIA on some of its branches with a common location ID: A042:B49C:D02E::72. Which WAN Edge configuration requirement?

The correct answer is D. vpn 0 interface ge0/0 ip address 172.16.0.1/24 nat vpn 1 ip route 0.0.0.0/0 vpn 0. For Direct Internet Access (DIA) at a branch, the WAN Edge's internet-facing interface and NAT must be configured in VPN 0, and service VPNs requiring internet access must have a default route pointing traffic to VPN 0.

WAN Edge Router Deployment

Question

An enterprise needs DIA on some of its branches with a common location ID: A042:B49C:D02E::72. Which WAN Edge configuration requirement?

Options

  • Avpn 1 interface ge0/1 ip address 172.16.0.1/24 vpn 512 ip route 0.0.0.0/0 vpn 0 vpn 1 nat
  • Bvpn 1 ip route 0.0.0.0/0 vpn 0 vpn 1 interface ge0/0 ip address 172.16.0.1/24 nat
  • Cvpn 0 ip route 0.0.0.0/0 vpn 0 vpn 1 interface ge0/1 ip address 172.16.0.1/24 nat
  • Dvpn 0 interface ge0/0 ip address 172.16.0.1/24 nat vpn 1 ip route 0.0.0.0/0 vpn 0

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    5% (1)
  • C
    5% (1)
  • D
    77% (17)

Why each option

For Direct Internet Access (DIA) at a branch, the WAN Edge's internet-facing interface and NAT must be configured in VPN 0, and service VPNs requiring internet access must have a default route pointing traffic to VPN 0.

Avpn 1 interface ge0/1 ip address 172.16.0.1/24 vpn 512 ip route 0.0.0.0/0 vpn 0 vpn 1 nat

This configuration places the internet-facing interface within VPN 1, which is a service VPN, rather than VPN 0 where transport interfaces for DIA are typically configured.

Bvpn 1 ip route 0.0.0.0/0 vpn 0 vpn 1 interface ge0/0 ip address 172.16.0.1/24 nat

This configuration also places the internet-facing interface within VPN 1 instead of VPN 0, which is incorrect for direct internet access.

Cvpn 0 ip route 0.0.0.0/0 vpn 0 vpn 1 interface ge0/1 ip address 172.16.0.1/24 nat

This configuration places the default route to VPN 0 within VPN 0 itself, which is redundant and incorrectly implies VPN 0 routes to itself. The internet-facing interface and NAT are also in VPN 1.

Dvpn 0 interface ge0/0 ip address 172.16.0.1/24 nat vpn 1 ip route 0.0.0.0/0 vpn 0Correct

This configuration correctly places the internet-facing interface ('ge0/0') and NAT within VPN 0, which is the transport VPN for direct internet access. It then correctly routes traffic from service VPN 1 to VPN 0 via a default route, allowing internal users to access the internet.

Concept tested: Direct Internet Access (DIA) configuration

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-direct-internet-access.html

Topics

#SD-WAN DIA#VPN 0#Service VPN#NAT

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice