300-415 · Question #49
In which VPN is the NAT operation on an outgoing interface configured for direct Internet access?
The correct answer is A. 0. In Cisco SD-WAN, NAT for direct Internet access is always configured within the transport VPN, which is specifically designated for this purpose.
Question
Options
- A0
- B512
- C10
- D1
How the community answered
(39 responses)- A90% (35)
- B5% (2)
- C3% (1)
- D3% (1)
Why each option
In Cisco SD-WAN, NAT for direct Internet access is always configured within the transport VPN, which is specifically designated for this purpose.
In Cisco SD-WAN, VPN 0 is designated as the transport VPN and is where interfaces connecting to the underlying physical network, including the Internet, are configured. Therefore, NAT for outgoing direct Internet access is always configured on an interface within VPN 0 to translate private IP addresses from service VPNs.
VPN 512 is typically reserved for out-of-band management traffic and is not used for direct Internet access with NAT.
VPN 10 is a service VPN, used for user data traffic. Any traffic from VPN 10 destined for the Internet is routed to VPN 0 for NAT and egress.
VPN 1 is also a service VPN, similar to VPN 10, and routes its Internet-bound traffic through VPN 0 for NAT.
Concept tested: NAT for Internet access in VPN 0
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/nat/nat-book.html#configuring-nat-with-a-local-internet-breakout-on-cisco-sd-wan-devices
Topics
Community Discussion
No community discussion yet for this question.