400-007 · Question #357
A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS…
The correct answer is A. Define a policy-based redirect to the applications. This question tests knowledge of how Cisco SD-WAN enables selective direct internet access (DIA) for specific SaaS applications at branch sites using traffic steering policies.
Question
A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS applications will be allowed direct internet access and all other internet-bound traffic will follow its usual path. The customer wants to leverage its existing SD-WAN solution and cloud provider integration. Which action must be taken on the remote branch routers to meet the requirements?
Options
- ADefine a policy-based redirect to the applications.
- BEnable Cloud OnRamp for the branch sites.
- CConfigure IPsec to the cloud provider.
- DImplement direct connect for site connectivity.
How the community answered
(24 responses)- A71% (17)
- B8% (2)
- C4% (1)
- D17% (4)
Why each option
This question tests knowledge of how Cisco SD-WAN enables selective direct internet access (DIA) for specific SaaS applications at branch sites using traffic steering policies.
In Cisco SD-WAN, a policy-based redirect (data policy configured in vManage) allows the administrator to match specific application traffic and redirect it to the local internet breakout interface, enabling direct internet access only for designated SaaS applications. All other traffic continues to follow the default SD-WAN overlay path, satisfying the requirement to selectively allow only certain applications to use the local broadband circuit.
Cloud OnRamp for SaaS optimizes the SD-WAN path to SaaS providers across the overlay fabric but does not by itself configure selective local internet breakout policies for specific applications at branch sites.
Configuring IPsec to the cloud provider establishes a private tunnel to cloud infrastructure and does not address selective direct internet access for SaaS applications using existing local broadband.
Direct connect is a dedicated private circuit solution to cloud providers such as AWS Direct Connect or Azure ExpressRoute, which is incompatible with using local broadband internet circuits for DIA.
Concept tested: SD-WAN policy-based redirect for selective DIA
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/policies/ios-xe-17/policies-book-xe/m-traffic-policies.html
Topics
Community Discussion
No community discussion yet for this question.