300-415 Question 233
Single answerAn enterprise is implementing Cisco SD-WAN with TrustSec to provide secure segmentation across the network. The administrator is tasked with ensuring that the TrustSec Security Group Tags (SGTs) are correctly propagated across the SD-WAN fabric. Which configuration step is required to achieve this?
- A
Enable SGT propagation under the VPN interface configuration on each WAN Edge.
- B
Configure the SGT-to-VPN mapping in vSmart policy.
- C
Enable TrustSec integration in the vManage device template for WAN Edge devices.
- D
Integrate ISE with vManage to dynamically assign SGTs across the SD-WAN fabric.
Show answer and explanation
Correct answer: A
Explanation
To propagate Security Group Tags (SGTs) across the Cisco SD-WAN fabric, it is necessary to enable SGT propagation under the VPN interface configuration on each WAN Edge device. This allows the tags to be carried in the data plane traffic, ensuring secure segmentation across the network. Other options mentioned may support TrustSec functionality but do not directly handle the propagation of SGTs.
- A. Correct.
Correct. Enabling SGT propagation under the VPN interface configuration on each WAN Edge ensures that the Security Group Tags are carried across the SD-WAN fabric.
- B. Incorrect.
Incorrect. SGT-to-VPN mapping in vSmart policy is not a valid method for propagating SGTs; it is not related to TrustSec propagation.
- C. Incorrect.
Incorrect. Enabling TrustSec integration in the vManage template does not directly propagate SGTs. This step is not sufficient to achieve the desired outcome.
- D. Incorrect.
Incorrect. While integrating ISE with vManage is important for dynamic SGT assignments, it does not directly handle SGT propagation across the SD-WAN fabric.