nerdexam
Cisco

300-415 · Question #438

Based on the provided SDWAN topology and route configuration, to steer VPN 1 traffic from sites 101 and 103 through the firewall at site 102, how must the centralized route policy be applied?

The correct answer is A. outbound, toward sites 101 and 103. A centralized route policy applied outbound toward sites 101 and 103 modifies the routes those sites receive, causing them to forward VPN 1 traffic through the firewall service at site 102.

Policies

Question

Based on the provided SDWAN topology and route configuration, to steer VPN 1 traffic from sites 101 and 103 through the firewall at site 102, how must the centralized route policy be applied?

Options

  • Aoutbound, toward sites 101 and 103
  • Binbound, toward sites 101 and 103
  • Coutbound, toward site 102
  • Dinbound, toward site 102

How the community answered

(35 responses)
  • A
    74% (26)
  • B
    9% (3)
  • C
    14% (5)
  • D
    3% (1)

Why each option

A centralized route policy applied outbound toward sites 101 and 103 modifies the routes those sites receive, causing them to forward VPN 1 traffic through the firewall service at site 102.

Aoutbound, toward sites 101 and 103Correct

Applying the route policy outbound toward sites 101 and 103 means the vSmart controller modifies OMP route advertisements sent to those sites, injecting service-node (firewall) information so that sites 101 and 103 send VPN 1 traffic to site 102 for firewall inspection before reaching the destination.

Binbound, toward sites 101 and 103

Inbound toward sites 101 and 103 means the policy processes routes those sites advertise into the vSmart, affecting what the vSmart stores rather than what routing information the sites receive.

Coutbound, toward site 102

Applying the policy outbound toward site 102 modifies routes sent to the firewall hub, not the routes that sites 101 and 103 use to forward traffic, so service insertion at 102 would not be triggered.

Dinbound, toward site 102

Inbound toward site 102 processes routes advertised by the firewall site into the vSmart and has no effect on how sites 101 and 103 route their traffic.

Concept tested: SD-WAN centralized route policy direction for service insertion

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/ios-xe-17/policies-book-xe/centralized-policy.html

Topics

#Centralized Route Policy#Traffic Steering#vSmart Policies#Policy Application

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice