5V0-42.21 · Question #1
An Enterprise customer just acquired a new company, and the Network Enterprise administrator was tasked to integrate over 20 new branches into their existing SD-WAN network. However, these branches…
The correct answer is B. Configure a LAN-side NAT rule at the branch device settings, translating its subnets into a new. Option B is correct because VMware SD-WAN (VeloCloud) provides a dedicated LAN-side NAT feature configured directly on the branch Edge device. This translates the branch's overlapping LAN subnets into unique, non-overlapping addresses before traffic enters the SD-WAN overlay…
Question
An Enterprise customer just acquired a new company, and the Network Enterprise administrator was tasked to integrate over 20 new branches into their existing SD-WAN network. However, these branches have overlapping IPs with the existing branches subnets.
Options
- AConfigure a NAT hand off rule at the VMware SD WAN gateway assigned to these new blanches,
- BConfigure a LAN-side NAT rule at the branch device settings, translating its subnets into a new
- CConfigure a NAT firewall rule in each branch, translating its subnets into a new non-overlapping
- DConfigure a policy based NAT tor each branch translating its subnets Into a new non-overlapping
How the community answered
(22 responses)- A9% (2)
- B82% (18)
- C5% (1)
- D5% (1)
Explanation
Option B is correct because VMware SD-WAN (VeloCloud) provides a dedicated LAN-side NAT feature configured directly on the branch Edge device. This translates the branch's overlapping LAN subnets into unique, non-overlapping addresses before traffic enters the SD-WAN overlay - solving the IP conflict at the source without touching the rest of the network.
Why the distractors are wrong:
- A is wrong because the SD-WAN Gateway operates on the WAN/cloud side; it doesn't manage LAN-subnet NAT for branch devices. NAT hand-off at the gateway is not the designed mechanism for resolving LAN overlap.
- C is wrong because NAT firewall rules are a different construct in VMware SD-WAN. Firewall policies handle traffic filtering, not LAN subnet remapping - using them for this purpose is not the supported or recommended approach.
- D is wrong because "policy-based NAT" is terminology from traditional firewall/router platforms (e.g., Cisco ASA). VMware SD-WAN does not expose this as a named feature; the platform-specific solution is LAN-side NAT in the Edge device settings.
Memory tip: Remember "LAN problem → LAN-side NAT at the Edge." Overlapping IPs are a LAN issue originating at the branch, so you fix it on the LAN side of the branch Edge device - not at a gateway, not in a firewall rule.
Topics
Community Discussion
No community discussion yet for this question.