300-415 Question 205
Single answerYou are implementing Cisco SD-WAN in your organization's network and need to configure service insertion to direct specific traffic through a firewall before it reaches its destination. You want to ensure this traffic passes through the firewall without disrupting other traffic flows. Which configuration step must you take to achieve this?
- A
Create a centralized control policy to match the traffic and redirect it to the firewall service.
- B
Enable Application-Aware Routing (AAR) to identify and redirect the traffic through the firewall.
- C
Use TLOC extension to configure a direct path to the firewall for all traffic.
- D
Configure a local data policy on the branch edge router to redirect matching traffic to the firewall.
Show answer and explanation
Correct answer: A
Explanation
Service insertion in Cisco SD-WAN requires the use of centralized control policies to redirect specific traffic to services like firewalls. This approach ensures consistent traffic handling and avoids disruptions to other flows. Application-Aware Routing and TLOC extension serve different purposes and are not used for service insertion. Similarly, local data policies operate only at the site level and lack the centralized control needed for this task.
- A. Correct.
Correct. A centralized control policy is used in Cisco SD-WAN to define traffic redirection to services such as firewalls. It allows precise control over which traffic is redirected without affecting other flows.
- B. Incorrect.
Incorrect. Application-Aware Routing (AAR) is used for path optimization based on application performance metrics and SLA requirements, not for service insertion.
- C. Incorrect.
Incorrect. TLOC extension is used to extend transport locators across devices, not for redirecting traffic through service insertion points.
- D. Incorrect.
Incorrect. While local data policies can modify traffic behavior at the site level, they are not the appropriate method for centralized service redirection in SD-WAN.