nerdexam
Palo_Alto_Networks

PCNSE · Question #404

What happens to traffic traversing SD-WAN fabric that doesn't match any SD-WAN policies?

The correct answer is C. Traffic matches implied policy rules and is redistributed round robin across SD-WAN links. If there is no match to any SD-WAN policy rule in the list, the session matches an implied SD- WAN policy rule at the end of the list that uses the round-robin method to distribute unmatched sessions among all links in one SD-WAN interface, which is based on the route lookup…

Submitted by ashley.k· Apr 18, 2026Operate

Question

What happens to traffic traversing SD-WAN fabric that doesn't match any SD-WAN policies?

Options

  • ATraffic is dropped because there is no matching SD-WAN policy to direct traffic.
  • BTraffic matches a catch-all policy that is created through the SD-WAN plugin.
  • CTraffic matches implied policy rules and is redistributed round robin across SD-WAN links.
  • DTraffic is forwarded to the first physical interface participating in SD-WAN based on lowest

How the community answered

(43 responses)
  • B
    5% (2)
  • C
    93% (40)
  • D
    2% (1)

Explanation

If there is no match to any SD-WAN policy rule in the list, the session matches an implied SD- WAN policy rule at the end of the list that uses the round-robin method to distribute unmatched sessions among all links in one SD-WAN interface, which is based on the route lookup. https://docs.paloaltonetworks.com/sd-wan/3-0/sd-wan-admin/configure-sd-wan/distribute- unmatched-sessions

Topics

#SD-WAN#Traffic Forwarding#Implied Policies#Default Behavior

Community Discussion

No community discussion yet for this question.

Full PCNSE Practice