5V0-42.21 · Question #49
A customer would like to use a VNF firewall on the VMware SU-WAN 600 series Edge. Where do the Edge firewall rules of the VNF apply?
The correct answer is C. WAN side. On the VMware SD-WAN 600 series Edge, VNF firewalls are inserted into the traffic path on the WAN side of the Edge appliance, meaning their rules are enforced on traffic ingressing and egressing the WAN interfaces before it enters the SD-WAN fabric. This placement allows the…
Question
A customer would like to use a VNF firewall on the VMware SU-WAN 600 series Edge. Where do the Edge firewall rules of the VNF apply?
Options
- AUnderlay
- BOverlay
- CWAN side
- DLAN side
How the community answered
(34 responses)- B3% (1)
- C91% (31)
- D6% (2)
Explanation
On the VMware SD-WAN 600 series Edge, VNF firewalls are inserted into the traffic path on the WAN side of the Edge appliance, meaning their rules are enforced on traffic ingressing and egressing the WAN interfaces before it enters the SD-WAN fabric. This placement allows the VNF to inspect and filter external/internet-facing traffic at the network perimeter.
Why the distractors are wrong:
- A (Underlay): The underlay refers to the physical transport network (ISP circuits); VNF rules operate at the application/service layer, not at the raw transport level.
- B (Overlay): The overlay is the SD-WAN virtual tunnel fabric; by the time traffic reaches the overlay, it has already passed through WAN-side processing - the VNF acts before the overlay encapsulation/decapsulation.
- D (LAN side): LAN-side enforcement is handled by Edge firewall policies and segmentation, not by the VNF firewall, which is positioned facing outward toward the WAN.
Memory tip: Think "VNF = perimeter guard" - it stands at the WAN Wall (WAN side), screening traffic before it ever touches the SD-WAN fabric inside.
Topics
Community Discussion
No community discussion yet for this question.