300-415 Question 246
Single answerA company has implemented Cisco SD-WAN and wants to enhance its internet security by integrating a Secure Internet Gateway (SIG). The IT team needs to route internet-bound traffic from branch sites through a SIG while maintaining central control over security policies. Which configuration approach should they use to achieve this?
- A
Configure a centralized data policy to redirect traffic to the SIG using a secure IPsec tunnel.
- B
Use Application-Aware Routing to dynamically route traffic to the SIG based on application performance.
- C
Enable Local Internet Breakout and configure each branch to connect directly to the SIG.
- D
Leverage OMP (Overlay Management Protocol) to automatically redirect traffic to the SIG.
Show answer and explanation
Correct answer: A
Explanation
To integrate a Secure Internet Gateway (SIG) into a Cisco SD-WAN deployment and ensure centralized control over internet-bound traffic, a centralized data policy is the most appropriate approach. This configuration allows secure redirection of traffic through an IPsec tunnel to the SIG, ensuring compliance with security policies while maintaining efficient traffic management.
- A. Correct.
Correct. Using a centralized data policy in Cisco SD-WAN ensures that internet-bound traffic is redirected to the SIG through a secure IPsec tunnel, maintaining centralized control over traffic and security policies.
- B. Incorrect.
Incorrect. Application-Aware Routing is used for optimizing application performance based on path quality, but it is not designed for redirecting traffic specifically to a SIG.
- C. Incorrect.
Incorrect. Enabling Local Internet Breakout allows each branch to access the internet directly but does not provide the centralized control required for routing traffic through a SIG.
- D. Incorrect.
Incorrect. OMP is used for routing and propagating routes in the Cisco SD-WAN overlay network but does not provide the capability to directly redirect traffic to a SIG.