- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2025 04:07 AM
Hi,
I have applied a centralized policy for DIA and also created a template, which I applied to a specific location. My question is: Which configuration will ultimately apply to the location?
In general, my question is: When we apply a configuration through a centralized policy and also apply the same configuration via a template, which one takes precedence and will be applied on a cEdge router?
Solved! Go to Solution.
- Labels:
-
SD-WAN Architecture
-
SD-WAN vManage
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-29-2025 05:33 PM
Hi,
when both are implemented, centralized data policy takes precedence for forwarding. Because in order of operations, it happens first before forwarding decision. It means, traffic on service-side will be put to VPN0 due to nat in centralized policy and router will not check service-side routing table anymore.
Picture is from SDWAN CVD:
Please rate and mark as an accepted solution if you have found any of the information provided useful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2025 04:08 AM
DIA need local policy not central policy
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2025 04:11 AM
We can also configure DIA via Centralzied policy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2025 04:32 AM
""Direct traffic from service VPN with either a static route or a centralized data policy."" <<- I prefer first op.
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-28-2025 04:34 AM
Regarding your message, the question is: When we direct traffic from the service VPN using either a template or a centralized policy, which configuration will ultimately take precedence and apply?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-29-2025 08:32 AM
It depends on the functions.
In case of DIA, I think there is no priority.
As you know, You can achieve DIA in 2 ways.
1. Feature Template > Service VPN > Static route
2. Centralized Policy > NAT VPN 0
The only difference is whether It is deployed by vSmart or Local Configuration.
* When It comes to Service Side NAT, It needs Centralized policy not only local configuration.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-29-2025 05:33 PM
Hi,
when both are implemented, centralized data policy takes precedence for forwarding. Because in order of operations, it happens first before forwarding decision. It means, traffic on service-side will be put to VPN0 due to nat in centralized policy and router will not check service-side routing table anymore.
Picture is from SDWAN CVD:
Please rate and mark as an accepted solution if you have found any of the information provided useful.
