300-415 Question 220
Single answerA company has deployed Cisco SD-WAN across its branch offices to enforce consistent security policies. The IT administrator wants to block specific categories of websites, such as social media and gaming, for all branch users. The administrator configures URL filtering policies on the vManage interface but notices that the policies are not being enforced. What could be the reason for this issue?
- A
The URL filtering feature is not enabled on the branch's WAN Edge routers.
- B
The vSmart controller is not configured to distribute URL filtering policies.
- C
The URL filtering policy is applied to the wrong VPN segment.
- D
The DNS server configuration is missing in the branch site routers.
Show answer and explanation
Correct answer: C
Explanation
URL filtering policies in Cisco SD-WAN need to be correctly applied to the intended VPN segment in order to take effect. Misconfiguring the VPN segment in vManage will result in the policy not being enforced on the targeted traffic. Ensuring the policy is applied to the correct VPN is crucial for its successful operation.
- A. Incorrect.
The URL filtering feature is automatically enabled on WAN Edge routers when configured via vManage. This is not a manual step that the administrator needs to perform.
- B. Incorrect.
vSmart controllers distribute security policies, including URL filtering, automatically as long as the policies are configured correctly in vManage.
- C. Correct.
URL filtering policies must be applied to the correct VPN segment (e.g., VPN 0, VPN 1, etc.) in the SD-WAN fabric. If the policy is applied to the wrong VPN, it will not affect the intended traffic.
- D. Incorrect.
DNS server configuration is unrelated to URL filtering enforcement. URL filtering works based on URL categories, not DNS resolution.