300-415 · Question #3
Which SD-WAN component is configured to enforce a policy to redirect branch-to-branch traffic toward a network service such as a firewall or IPS?
The correct answer is B. vSmart. The vSmart controller is the SD-WAN component responsible for enforcing centralized control policies, including service chaining to redirect traffic like branch-to-branch flows to network services.
Question
Options
- AvBond
- BvSmart
- CWAN Edge
- DFirewall
How the community answered
(22 responses)- A9% (2)
- B86% (19)
- C5% (1)
Why each option
The vSmart controller is the SD-WAN component responsible for enforcing centralized control policies, including service chaining to redirect traffic like branch-to-branch flows to network services.
vBond is the orchestrator, primarily used for initial authentication and coordination, not for policy enforcement.
The vSmart controller is the centralized brain of the Cisco SD-WAN solution, responsible for control plane operations and distributing policies. It is configured with centralized control or data policies to enforce traffic redirection (service chaining) for specific flows, such as sending branch-to-branch traffic to a firewall or IPS.
WAN Edge routers execute policies, but the policies themselves for centralized traffic redirection are configured and pushed from vSmart.
A firewall is a service device, not an SD-WAN component that configures or enforces SD-WAN policies.
Concept tested: vSmart centralized policy enforcement
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-xe-gs-book_chapter_0100.html
Topics
Community Discussion
No community discussion yet for this question.