nerdexam
Cisco

300-415 · Question #251

A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1. Which control policy configuration restricts these updates?

The correct answer is C. policy lists vpn-list VPN1 vpn 1 ! control-policy restrict_1 sequence 10 match route vpn-list VPN1 ! action reject ! default-action accept. To restrict outbound route updates for VPN1, a control policy must be configured to specifically match VPN1 routes and then apply a 'reject' action, with a default action to accept other VPN routes.

Policies

Question

A customer has 1 to 100 service VPNs and wants to restrict outbound updates for VPN1. Which control policy configuration restricts these updates?

Options

  • Apolicy lists vpn-list restricted_vpns vpn 2-100 ! vpn-membership restrict_1 sequence 10 match vpn-list restricted_vpns action reject ! default-action accept !
  • Bpolicy lists vpn-list VPN2-100 vpn 2-100 ! control-policy restrict_2-100 sequence 10 match route vpn-list VPN2-100 ! action reject ! default-action accept
  • Cpolicy lists vpn-list VPN1 vpn 1 ! control-policy restrict_1 sequence 10 match route vpn-list VPN1 ! action reject ! default-action accept
  • Dpolicy lists vpn-list restricted_vpns vpn 1 ! vpn-membership restrict_1 sequence 100 match vpn-list restricted_vpns action reject ! default-action accept !

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    6% (3)
  • C
    79% (37)
  • D
    13% (6)

Why each option

To restrict outbound route updates for VPN1, a control policy must be configured to specifically match VPN1 routes and then apply a 'reject' action, with a default action to accept other VPN routes.

Apolicy lists vpn-list restricted_vpns vpn 2-100 ! vpn-membership restrict_1 sequence 10 match vpn-list restricted_vpns action reject ! default-action accept !

This configuration uses 'vpn-membership', which is a different type of policy than a control policy for route updates, and it incorrectly matches VPNs 2-100 to reject them, which is the opposite of the requirement (reject VPN1).

Bpolicy lists vpn-list VPN2-100 vpn 2-100 ! control-policy restrict_2-100 sequence 10 match route vpn-list VPN2-100 ! action reject ! default-action accept

This control policy is designed to reject VPNs 2-100, not VPN1, which contradicts the stated goal of restricting outbound updates for VPN1.

Cpolicy lists vpn-list VPN1 vpn 1 ! control-policy restrict_1 sequence 10 match route vpn-list VPN1 ! action reject ! default-action acceptCorrect

This configuration correctly defines a 'vpn-list' specifically for VPN1. It then creates a 'control-policy' that matches routes belonging to this 'vpn-list' (VPN1) and applies an 'action reject', which effectively restricts outbound updates for VPN1. The 'default-action accept' ensures all other VPNs (2-100) are accepted.

Dpolicy lists vpn-list restricted_vpns vpn 1 ! vpn-membership restrict_1 sequence 100 match vpn-list restricted_vpns action reject ! default-action accept !

This configuration uses 'vpn-membership', which is not the correct policy type for restricting outbound route updates. It also uses a high sequence number (100) before a default accept, which might allow VPN1 routes to be accepted before the specific reject if other rules are present.

Concept tested: Cisco SD-WAN control policy for route filtering

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-policy-config.html#Cisco_Concept.dita_09c31326-8051-40b9-8086-538423402778

Topics

#SD-WAN Control Policy#VPN Filtering#vSmart Policy#Route Filtering

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice