SD-WAN Direct Internet Access for SaaS
A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS applications will be allowed direct internet access and all other internet-bound traffic will follow its usual path. The customer wants to leverage its existing SD-WAN solution and cloud provider integration. Which action must be taken on the remote branch routers to meet the requirements?
Community Votes
83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the distinction between SD-WAN application-aware routing (Policy-Based Redirect) and cloud interconnect services (Cloud OnRamp).
Configuring policy-based redirect allows specific SaaS traffic to bypass the central hub and use local internet, optimizing performance while maintaining security policies. This page clarifies why BGP/Cloud OnRamp is not required for generic SaaS direct breakout.
Candidates often select Cloud OnRamp because it involves 'cloud' and 'SD-WAN', but it is designed for connecting to Oracle/AWS/Azure private clouds, not general public internet SaaS.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Policy-Based Redirect (PBR) is the mechanism in Cisco SD-WAN that allows administrators to define specific traffic flows (based on applications or destinations) and steer them over a specific transport link, such as a local broadband internet circuit. This meets the requirement of allowing direct internet access for specific SaaS apps while keeping other traffic on the usual path (likely the MPLS or encrypted IPsec tunnel to the data center).Why the Other Options Are Wrong
Cloud OnRamp (B) is used to connect SD-WAN branches to specific IaaS providers like AWS, Azure, or OCI using VCN/VPC peering or transit gateways. It does not facilitate direct breakout to the public internet for arbitrary SaaS applications. IPsec (C) is a transport protocol, not a routing policy for breaking out specific traffic. Direct Connect (D) refers to AWS Dedicated Connections, which is an IaaS interconnect, not a branch SaaS optimization feature.Community Comment Notes
The community majority voted for B, likely confusing 'Cloud OnRamp' with any cloud-related SD-WAN feature. One commenter noted that enabling Cloud OnRamp routes specific cloud traffic directly, but this applies to private cloud interconnects, not general SaaS. Another user correctly identified A, explaining that PBR specifies which traffic goes where, aligning with the 'specific SaaS' requirement.Official Reference
Exam Strategy
When you see 'direct internet access' for specific apps in SD-WAN, think Policy-Based Redirect or Application-Aware Routing. Reserve Cloud OnRamp answers for questions mentioning AWS, Azure, OCI, or VPC/VCN integration.
Frequently Asked Questions
What is the difference between Policy-Based Redirect and Cloud OnRamp?
PBR steers traffic to local internet or specific tunnels based on app/dest. Cloud OnRamp connects branches to private IaaS clouds (AWS/Azure) via dedicated interconnects.
Can I use Cloud OnRamp for direct SaaS internet access?
No. Cloud OnRamp is for private cloud connectivity. For public SaaS apps breaking out locally, you must use Policy-Based Redirect or Local Breakout configurations.