nerdexam
Cisco

300-415 · Question #440

An engineer is creating a policy for VPN1 users. Their scavenger traffic at site 101 must pass through a firewall. Which two match conditions must be selected to enable this policy? (Choose two.)

The correct answer is B. application/application family list C. source data prefix. To identify scavenger-class traffic from site 101 users and steer it through a firewall, the policy must match both the application type (scavenger category) and the source network prefix of the users.

Policies

Question

An engineer is creating a policy for VPN1 users. Their scavenger traffic at site 101 must pass through a firewall. Which two match conditions must be selected to enable this policy? (Choose two.)

Options

  • Aprotocol
  • Bapplication/application family list
  • Csource data prefix
  • Dpacket length
  • Edestination port

How the community answered

(59 responses)
  • A
    8% (5)
  • B
    83% (49)
  • D
    5% (3)
  • E
    3% (2)

Why each option

To identify scavenger-class traffic from site 101 users and steer it through a firewall, the policy must match both the application type (scavenger category) and the source network prefix of the users.

Aprotocol

'protocol' alone identifies IP protocol numbers (TCP/UDP) but cannot distinguish scavenger traffic from other traffic sharing the same protocol, making it insufficient for this use case.

Bapplication/application family listCorrect

The 'application/application family list' match condition identifies scavenger traffic by its application classification (DSCP CS1 or low-priority application family), which is the standard way to classify scavenger-class flows in SD-WAN data policy.

Csource data prefixCorrect

The 'source data prefix' match condition scopes the policy to traffic originating from site 101 users' subnet, ensuring only VPN 1 users at that site are subject to the firewall steering policy.

Dpacket length

'packet length' is unrelated to QoS traffic classification and does not identify scavenger-class flows.

Edestination port

'destination port' identifies specific application ports but scavenger class spans many applications and ports, making a single port match inadequate to capture the full scavenger traffic category.

Concept tested: SD-WAN data policy match conditions for application-based traffic steering

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/ios-xe-17/policies-book-xe/data-policy.html

Topics

#Policy Matching#Traffic Classification#SD-WAN Security#VPN Policies

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice