300-415 · Question #305
Which type of connection is created between a host VNet and a transit VNet when configuring Cloud OnRamp for Iease?
The correct answer is C. IPsec turtle. When configuring Cloud OnRamp for IaaS in an Azure environment, an IPsec tunnel is established between the host VNet and a transit VNet to facilitate secure and encrypted connectivity to the SD-WAN fabric.
Question
Options
- AGRE tunnel
- BAzure peer link
- CIPsec turtle
- DAzure private endpoint
How the community answered
(32 responses)- A6% (2)
- B3% (1)
- C88% (28)
- D3% (1)
Why each option
When configuring Cloud OnRamp for IaaS in an Azure environment, an IPsec tunnel is established between the host VNet and a transit VNet to facilitate secure and encrypted connectivity to the SD-WAN fabric.
GRE tunnels are used for specific routing needs but are not the primary secure connection type established by Cloud OnRamp for IaaS between VNets for data plane security.
Azure peer links (VNet peering) connect VNets within Azure but do not provide the secure overlay connectivity orchestrated by Cloud OnRamp for IaaS with the SD-WAN fabric.
Cloud OnRamp for IaaS, especially for Azure, utilizes IPsec tunnels to create secure, encrypted connections between the on-premises SD-WAN network and the Azure VNet via a transit VNet, ensuring secure data transfer for cloud workloads.
Azure private endpoints offer private access to Azure services, but they are not used for creating network-to-network secure connections for SD-WAN integration between VNets.
Concept tested: Cloud OnRamp for IaaS connection type
Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/SD-WAN/cloud-onramp-azure-sd-wan/cloud-onramp-azure-sd-wan-guide.html
Topics
Community Discussion
No community discussion yet for this question.