D is correct per page 266 of the guide:
"SD-WAN supports ADVPN shortcuts. For this, SD-WAN automatically steers the traffic through shortcuts and monitors their health and performance. You add the parent tunnel as member, and after the shortcut is negotiated, SD-WAN automatically starts steering traffic through the shortcut."
C is INCORRECT for the same reason D is correct: "you add the parent tunnel as member." There is no discussion of (nor is there any need to) add the physical interface to the overlay zone -- only the tunnel interface need be added.
Correction ^^
There is no discussion that adding the physical interface will prevent SD-WAN from steering traffic over the member tunnel interface. I agree it is an incorrect configuration (physical interface SHOULD NOT be a member), but ADVPN/SD-WAN shortcut steering will still work.
A - Wrong
B - Wrong
D - Wrong - SD-WAN supports ADVPN shortcuts. For this, SD-WAN automatically steers the traffic through shortcuts and monitors their health and performance. You add the parent tunnel as member, and after the shortcut is negotiated, SD-WAN automatically starts steering the traffic through the shortcut
Lets say that the parent interface is called ADVPN and an example of a shortcut will be ADVPN1_0 . You do not add in the zone the ADVPN1_0 as described on choice D you add the parent tunnel. I am not really sure how all people gave as an answer D as correct. Its a tricky one as they play with words.
C is the correct one. SD-WAN ADVPN is an overlay solution so it not expected to use the physical interfaces as members when specifically at C it says "established over IPSEC overlays"
Just because it is not expected to have the physical interface in the zone does not mean it will not work. C is INCORRECT because it states that "SD-WAN cannot steer traffic" if the zone contains physical interfaces. This is not true. You could have a physical interface in the zone. Since there is no valid route out that interface, that member will never be used, but the SD-WAN will still steer traffic over the IPSec overlay.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
ccie8122
1 month, 4 weeks agoccie8122
1 month, 4 weeks agoGCISystemIntegrator
6 months, 1 week agosugar12
7 months agoccie8122
1 month, 4 weeks agostbb
6 months agotruserud
8 months, 1 week agoalejandrofern43
9 months, 1 week agoKavinT
9 months, 3 weeks agoIBB90704
9 months, 3 weeks ago