300-415 Question 244
Single answerAn organization has deployed Cisco SD-WAN with a Secure Internet Gateway (SIG) integration for secure cloud access. The IT team wants to ensure that all branch office traffic destined for SaaS applications is inspected and filtered before reaching the internet. Which configuration step is necessary to enable the traffic redirection to the SIG service?
- A
Configure a SIG template in Cisco vManage and attach it to the branch devices.
- B
Enable IPSec tunnels between branch routers and the SIG service.
- C
Deploy a local DNS server at each branch office to resolve SIG service URLs.
- D
Configure a centralized data policy in Cisco vManage to forward branch traffic to the SIG service.
Show answer and explanation
Correct answer: D
Explanation
To integrate Cisco SD-WAN with a Secure Internet Gateway (SIG) for secure cloud access, a centralized data policy must be configured in Cisco vManage. The data policy ensures that traffic from branch offices destined for SaaS applications or the internet is redirected to the SIG for inspection, filtering, and other security measures. This is crucial for enforcing security policies and protecting the organization's network from threats.
- A. Incorrect.
While SIG templates are used to define SIG settings, they do not handle the actual traffic redirection. Traffic redirection requires data policy configuration.
- B. Incorrect.
IPSec tunnels are typically used for secure communication, but they are not sufficient on their own to redirect traffic to a SIG service.
- C. Incorrect.
Deploying a local DNS server is not required for SIG integration. The SIG service uses global DNS resolution and policies for traffic redirection.
- D. Correct.
Configuring a centralized data policy in Cisco vManage is the correct step to redirect branch traffic to the SIG service. This ensures that traffic is routed through the secure internet gateway for inspection and filtering.