300-415 Question 204
Single answerYou are configuring service insertion in a Cisco SD-WAN deployment to redirect traffic through a third-party security appliance for deep packet inspection (DPI). After configuring the service chaining in the vManage dashboard, users report that traffic is bypassing the security appliance and not being inspected. Which step should you verify to ensure proper service insertion?
- A
Verify that the service VPN is correctly configured on the devices where service insertion is applied.
- B
Ensure that the SD-WAN controllers are running the latest firmware version.
- C
Check if the data policies for redirecting traffic to the service appliance are properly applied in vManage.
- D
Verify that the service appliance is reachable and has the correct routing configured.
Show answer and explanation
Correct answer: C
Explanation
Service insertion in Cisco SD-WAN relies heavily on data policies configured in vManage to redirect traffic to the intended service appliance. If these policies are not correctly configured or applied, traffic will not be redirected and will bypass the service. While other factors like service VPNs, firmware, and appliance reachability are important, they do not directly address the issue of traffic bypassing the appliance.
- A. Incorrect.
While service VPN configuration is important, it is not specific to ensuring proper traffic redirection through the service appliance. The issue described relates to bypassing the service, which is likely caused by policy misconfiguration.
- B. Incorrect.
Upgrading firmware can address bugs, but it is not directly related to the issue of traffic bypassing the service appliance. The problem is more likely related to configuration rather than software version.
- C. Correct.
Data policies in Cisco SD-WAN are critical for redirecting traffic to a service appliance. If these policies are not correctly configured or applied, traffic will bypass the appliance, which matches the described issue.
- D. Incorrect.
Although the service appliance's reachability and routing are necessary, they would typically result in traffic drops (if unreachable) rather than bypassing the appliance. The issue described points to a policy misconfiguration.