exam questions

Exam 300-415 All Questions

View all questions & answers for the 300-415 exam

Exam 300-415 topic 1 question 29 discussion

Actual exam question from Cisco's 300-415
Question #: 29
Topic #: 1
[All 300-415 Questions]

Company E wants to deploy Cisco SD-WAN with controllers in AWS. The company's existing WAN is on private MPLS without Internet access to controllers in
AWS. An Internet circuit is added to a site in addition to the existing MPLS circuit. Which interface template establishes BFD neighbors over both transports?
A.

B.

C.

D.

Show Suggested Answer Hide Answer
Suggested Answer: A

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Arsenal16
4 months, 1 week ago
I think B is correct. When the Restrict option is turned On, it may limit the traffic to only specific paths or interfaces, which can interfere with the establishment of BFD neighbors across both the MPLS and Internet links.
upvoted 1 times
...
John662266
6 months ago
I think B is correct.
upvoted 3 times
...
ckdwa123
8 months, 1 week ago
I also believe it is B. https://community.cisco.com/t5/sd-wan-and-cloud-networking/cisco-sdwan-mpls-transport/td-p/4759812 It is similar thing and you force for max cc as 0 to not form control connections with controllers but you still force other tlocs to advertise this tloc in order to build data plane over it. "If that is true you can update the MPLS interface (under tunnel-interface) with "max-control-connections 0". This command will force the other two transports (gold, green) that can connect to the controllers to send the MPLS interface TLOC info to the controllers." If we choose vBond as Stun Server, it doesn't make sense as there is no NAT done in the MPLS circuit so how would it help? Private colors are not intended to be used with NAT. "On the other hand, private colors are intended for use on connections to clouds where NAT is not utilized"
upvoted 3 times
...
Vinay_Harish
1 year, 3 months ago
I suppose D is the correct answer, due to reasons below, 1. As per the question "which interface template establishes BFD neigh over both interface". Which means we need to allow at least 1 control connections on each of the links in-order to form the control connections and in-turn the BFD neigh.
upvoted 1 times
...
RafaJohnston76
1 year, 4 months ago
B is correct As per requirements of the question the only correct answer is B, here is what I found on a book: For transports that don’t need to facilitate control connectivity to the controllers (such as with MPLS, wherein the controllers are only reachable via the Internet), you must restrict control connections via the max- control- connections 0 command. This command is applied to the transport tunnel interface.
upvoted 2 times
...
hamed4maf
1 year, 5 months ago
B is correct because MPLS is not used for control connection and must max-control-connection on this interface be 0 A is not correct, because restrict is one of the OMP attributes that using for data plane not control plane C is not correct, because vbond use as a stun server when other controllers alos put on cloud D is not correct, because when we use internet connection for vbond connectio, we must max-control-connection = 0 on MPLS
upvoted 1 times
...
Aldebeer
1 year, 6 months ago
B is correct
upvoted 2 times
...
Clouddon
1 year, 8 months ago
D is correct
upvoted 3 times
...
creaakz
1 year, 9 months ago
"Which interface template establishes BFD neighbors over both transports?" That immediately rules out the Restrict option. B is correct, you don't want to establish control connection through the MPLS link (since it doesn't reach the controllers).
upvoted 1 times
...
AJMD
1 year, 10 months ago
B is correct
upvoted 2 times
...
begafas
1 year, 10 months ago
B is the corect answer. If MPLS doesn't have access to the controllers, only max-control-connections to 0 will allow it to form BFD tunnels on MPLS link.
upvoted 2 times
...
NetArch_Teck
1 year, 10 months ago
A is the correct Answer. Please remember the question specifies an existing topology of an MPLS TLOC, so you want to restrict this to MPLS, and leave the maximum connections ticked. This would complete the question. I have also rolled out this policy to the controllers for a customer where they added two circuits to an existing topology being MPLS from a ISP.
upvoted 1 times
...
hamidreza0010
1 year, 11 months ago
D is the correct answer
upvoted 2 times
...
JP4CCNP
2 years ago
B is the correct answer: - vBond isn`t reachable via MPLS (as explaint in the Text) -> so C can`t be the right answere - onyl 1 Controll Session make no sense, because vSmarts are also Controllers and not reachable vie MPLS (as explaint in the Text) -> So D can`t be the right answere - Answere A limits the IPSEC Tunnels to the color MPLS (but for this, the Controllers DTLS Session must be formed to learn and advertise OMP Routes) - Answere B can only the right Answere, because with setting the max. Controll Sesisons to 0 we told the Edge Device it is not possible to form Control Sessions about this MPLS link and the Edge Device advertise about the existing Internet Control Sessions the MPLS Color TLOCs to the vSmart. This Help to build IPSEC Tunnel over Private Links without creating Control Tunnels over this Cloud!
upvoted 4 times
Tuchi
1 year, 11 months ago
The key here is the BFD neighbors
upvoted 2 times
...
...
hamidreza0010
2 years, 1 month ago
D is the correct answer
upvoted 1 times
...
densma
2 years, 1 month ago
B is the only correct answer
upvoted 3 times
...
bearsaxman
2 years, 4 months ago
This should be B. The question specifically states that the MPLS link has no connectivity to the controllers in AWS. Without configuring max-control-connections to 0, BFD sessions will not form on the MPLS link. The restrict option, while desirable, is not necessary. Tunnels will attempt from mpls<->biz-internet and will fail, but mpls<->mpls and biz-internet<->biz-internet tunnels will still form. Per Cisco Press's SD-WAN Book: "When a WAN Edge attempts to join the fabric, it attempts to build control connections across each transport deployed at that site. By default, if a transport doesn’t have control connectivity to any of the Cisco SD-WAN controllers, then it won’t build a data plane connection across that transport either. This is very common with cloud deployments where the controllers are in a public or private cloud and your MPLS transport has no connectivity to the Internet." Followed by this note: "There are a few options to still achieve data plane with no control connectivity. One option is to disable control connections on that transport via the max-control-connections command. "
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...