nerdexam
Cisco

300-620 · Question #176

An engineer configures a one-armed policy-based redirect service Insertion for an unmanaged firewall. The engineer configures these Cisco ACI objects: - a contract named All_Traffic_Allowed - a Layer

The correct answer is D. Configure a service graph.. To configure a one-armed policy-based redirect (PBR) service insertion for an unmanaged firewall, a service graph is the crucial ACI object that orchestrates traffic redirection.

ACI Integrations

Question

An engineer configures a one-armed policy-based redirect service Insertion for an unmanaged firewall. The engineer configures these Cisco ACI objects:

  • a contract named All_Traffic_Allowed
  • a Layer 4 to Layer 7 device named FW-Device
  • a policy-based redirect policy named FW-1Arm-Policy-Based

RedirectPolicy Which configuration set redirects the traffic to the firewall?

Options

  • AConfigure a policy-based redirect subject.
  • BConfigure a firewall bridge domain.
  • CConfigure a device interface policy.
  • DConfigure a service graph.

How the community answered

(45 responses)
  • A
    4% (2)
  • B
    4% (2)
  • C
    13% (6)
  • D
    78% (35)

Why each option

To configure a one-armed policy-based redirect (PBR) service insertion for an unmanaged firewall, a service graph is the crucial ACI object that orchestrates traffic redirection.

AConfigure a policy-based redirect subject.

A policy-based redirect subject is a component of a PBR policy, but it does not orchestrate the entire service insertion and traffic redirection workflow, which requires a service graph.

BConfigure a firewall bridge domain.

A firewall bridge domain might be part of the firewall's network configuration or its ACI integration, but it does not directly configure the traffic redirection logic.

CConfigure a device interface policy.

A device interface policy configures properties of interfaces on the L4-L7 service device, but it does not define how traffic is redirected to that device for service insertion.

DConfigure a service graph.Correct

A service graph in Cisco ACI is used to chain a contract with a service device like a firewall and apply specific service policies, including policy-based redirect. It defines the complete traffic flow and redirection path through the L4-L7 service device, making it essential for service insertion.

Concept tested: Cisco ACI Service Graph for PBR

Source: https://www.cisco.com/c/en/us/td/docs/dcn/aci/apic/6x/l4-l7-services/cisco-aci-l4l7-service-insertion-guide-60x/m_configuring-pbr.html

Topics

#service graph#PBR#L4-L7 device integration#firewall redirection

Community Discussion

No community discussion yet for this question.

Full 300-620 Practice