300-415 Question 207
Select 3Your organization has deployed a Cisco SD-WAN solution and requires traffic from specific applications to be routed through an external firewall for advanced security inspection. Which steps must you take to configure service insertion in the Cisco SD-WAN solution?
- A
Configure a centralized data policy to redirect traffic to the service node.
- B
Define the external firewall as a service in the vManage GUI under the Configuration > Services section.
- C
Assign the service node to specific VPNs within the device templates.
- D
Enable Application-Aware Routing on the vEdge devices to prioritize traffic to the service node.
- E
Provision the service node as a virtual machine in the vSmart controller.
Show answer and explanation
Correct answers: A, B, C
Explanation
Service insertion in Cisco SD-WAN requires configuring a centralized data policy to redirect traffic, defining the external firewall or service in vManage, and associating it with specific VPNs to ensure traffic flows through the service node. Application-Aware Routing and provisioning a service node in vSmart are unrelated to service insertion.
- A. Correct.
Correct: A centralized data policy is required to redirect traffic to the service node or firewall for advanced inspection.
- B. Correct.
Correct: Defining the external firewall as a service in vManage is an essential configuration step for service insertion.
- C. Correct.
Correct: The service node must be associated with specific VPNs in the device templates to ensure proper traffic redirection.
- D. Incorrect.
Incorrect: Application-Aware Routing is not directly related to configuring service insertion. It is used to dynamically route traffic based on application performance metrics.
- E. Incorrect.
Incorrect: The service node is not provisioned as a virtual machine in the vSmart controller. Instead, it is typically an external device or service.