300-415 · Question #226
Which type of policy must be applied on a WAN Edge application-aware firewall to control traffic between two or more VPNs?
The correct answer is A. firewall policy. To control traffic between different VPNs using a WAN Edge application-aware firewall, a firewall policy must be applied. This policy defines specific rules for permitting, denying, or logging traffic based on various criteria.
Question
Exhibit
Options
- Afirewall policy
- Bdata policy
- Cservice-insertion policy
- Dcontrol policy
How the community answered
(53 responses)- A89% (47)
- B4% (2)
- C6% (3)
- D2% (1)
Why each option
To control traffic between different VPNs using a WAN Edge application-aware firewall, a firewall policy must be applied. This policy defines specific rules for permitting, denying, or logging traffic based on various criteria.
A firewall policy, specifically an application-aware firewall policy, is designed to inspect and control traffic flows based on applications, protocols, and ports, and it is the correct mechanism to regulate traffic between different VPNs on a WAN Edge router.
Data policies are used to influence data plane traffic forwarding decisions, such as path selection or QoS, rather than acting as a firewall to permit or deny traffic between VPNs.
Service-insertion policies are used to redirect traffic to external services like firewalls or IPS systems, not to define the firewall rules themselves.
Control policies influence the control plane, affecting routing information and TLOC selection, not directly filtering traffic on the data plane like a firewall.
Concept tested: SD-WAN Application-Aware Firewall Policy
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-security.html#concept_q5j_2s1_ynb
Topics
Community Discussion
No community discussion yet for this question.
