300-415 · Question #209
Which device should be configured with the service chain IP address to route intersite traffic through a firewall?
The correct answer is C. hub WAN Edge. For intersite service chaining through a firewall, the hub WAN Edge router is configured with the service chain IP address to direct traffic to the firewall.
Question
Options
- AvSmart
- Bspoke WAN Edge
- Chub WAN Edge
- DFirewall
How the community answered
(68 responses)- A1% (1)
- B7% (5)
- C87% (59)
- D4% (3)
Why each option
For intersite service chaining through a firewall, the hub WAN Edge router is configured with the service chain IP address to direct traffic to the firewall.
vSmart controllers define and distribute policies but do not directly handle data plane traffic forwarding or service chain IP addresses for data plane steering.
Spoke WAN Edge routers typically forward traffic to the hub for intersite communication and do not usually host the central service chain IP for a shared firewall.
In a service chaining scenario for intersite traffic, the hub WAN Edge router acts as the point of insertion for the firewall. It is configured with the service chain IP address (often a next-hop IP for traffic going to the firewall) to steer intersite traffic to the firewall before it proceeds to its final destination.
The firewall itself would have its own IP address, but the SD-WAN device that is configured to send traffic to the firewall using a service chain IP is the hub WAN Edge.
Concept tested: Service chaining with hub WAN Edge
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-security-configuration.html
Topics
Community Discussion
No community discussion yet for this question.