05-28-2021 05:45 AM
Hi community,
i got a question about firewall service insertion, this can be consider control policy or data policy in SD-WAN?
Solved! Go to Solution.
05-28-2021 12:18 PM
Hi,
both centralized control and data policy can be used for service chaining:
To route traffic through a service, you provision either a control policy or a data policy on the Cisco vSmart Controller. You use a control policy if the match criteria are based on a destination prefix or any of its attributes. You use a data policy if the match criteria include the source address, source port, DSCP value, or destination port of the packet or traffic flow
Regards,
05-28-2021 06:00 AM
Most cases FW in the path for both, you can allow what required for SDWAN to establish DTLS / IPSEC with Cloud devices.
05-28-2021 06:14 AM
Thx you balaji bandi,
the thing is yesterday i fail the sd wan 300-415 exam and there was a question about that....
so, i think it can be consider control policy because in the policy normally i see the configuration there...
05-28-2021 06:59 AM
Since i was not sure what the question it hard to guess what you got there, if you can elaborate or post the question we may understand better to give reasonable answer.
05-28-2021 07:29 AM
in the exam basically ask me about the firewall service insertion is considered an:
control policy
data policy
and other 2 options i dont remember but something with no sense like bgp & ospf
the thing is im not 100% sure if the service insertion is always a control policy in sd wan
05-28-2021 12:18 PM
Hi,
both centralized control and data policy can be used for service chaining:
To route traffic through a service, you provision either a control policy or a data policy on the Cisco vSmart Controller. You use a control policy if the match criteria are based on a destination prefix or any of its attributes. You use a data policy if the match criteria include the source address, source port, DSCP value, or destination port of the packet or traffic flow
Regards,
05-28-2021 12:46 PM
Thx you that was what I was looking for
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide