nerdexam
Cisco

300-415 · Question #226

Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?

The correct answer is A. firewall policy. To control traffic between different VPNs using a WAN Edge application-aware firewall, a firewall policy must be applied. This policy defines specific rules for permitting, denying, or logging traffic based on various criteria.

Policies

Question

Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?

Exhibit

300-415 question #226 exhibit

Options

  • Afirewall policy
  • Bdata policy
  • Cservice-insertion policy
  • Dcontrol policy

How the community answered

(53 responses)
  • A
    89% (47)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Why each option

To control traffic between different VPNs using a WAN Edge application-aware firewall, a firewall policy must be applied. This policy defines specific rules for permitting, denying, or logging traffic based on various criteria.

Afirewall policyCorrect

A firewall policy, specifically an application-aware firewall policy, is designed to inspect and control traffic flows based on applications, protocols, and ports, and it is the correct mechanism to regulate traffic between different VPNs on a WAN Edge router.

Bdata policy

Data policies are used to influence data plane traffic forwarding decisions, such as path selection or QoS, rather than acting as a firewall to permit or deny traffic between VPNs.

Cservice-insertion policy

Service-insertion policies are used to redirect traffic to external services like firewalls or IPS systems, not to define the firewall rules themselves.

Dcontrol policy

Control policies influence the control plane, affecting routing information and TLOC selection, not directly filtering traffic on the data plane like a firewall.

Concept tested: SD-WAN Application-Aware Firewall Policy

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-security.html#concept_q5j_2s1_ynb

Topics

#SD-WAN Policy#Firewall Policy#WAN Edge#VPN Segmentation

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice