300-415 Question 206
Single answerA company has deployed a Cisco SD-WAN solution and wants to redirect specific traffic through a firewall for deep packet inspection before allowing it to reach the destination. Which configuration step is required to achieve service insertion in this scenario?
- A
Define a centralized data policy that matches the traffic criteria and applies an action to redirect traffic to the firewall service.
- B
Enable service chaining on the vEdge devices and specify the firewall as a mandatory hop for the traffic.
- C
Configure a localized control policy on the vSmart controller to enforce the firewall redirection.
- D
Create a VPN segmentation policy on the vBond orchestrator to route the traffic through the firewall.
Show answer and explanation
Correct answer: A
Explanation
To achieve service insertion in Cisco SD-WAN, a centralized data policy must be defined on the vSmart controller. This policy matches the traffic that needs to be redirected and specifies an action to steer the traffic through the desired service, such as a firewall. Service insertion ensures that specific traffic flows pass through intermediate services for inspection or processing.
- A. Correct.
This is correct. Service insertion in Cisco SD-WAN requires defining a centralized data policy on the vSmart controller that matches the traffic criteria and redirects it to the firewall service.
- B. Incorrect.
This is incorrect. Service chaining is not directly configured on vEdge devices in Cisco SD-WAN; it is achieved using centralized data policies on the vSmart controller.
- C. Incorrect.
This is incorrect. Control policies in SD-WAN are used for routing decisions, not for traffic redirection through services like firewalls.
- D. Incorrect.
This is incorrect. VPN segmentation policies are used to isolate traffic between VPNs, not to redirect traffic through specific services.