SD-WAN Direct Internet Access for SaaS

Answer Correct answer: A — Define a policy-based redirect to the applications.

A large enterprise plans to enable direct internet access for specific SaaS applications from its remote branch sites by using local broadband internet circuits. Only traffic to specific cloud SaaS applications will be allowed direct internet access and all other internet-bound traffic will follow its usual path. The customer wants to leverage its existing SD-WAN solution and cloud provider integration. Which action must be taken on the remote branch routers to meet the requirements?

  1. Define a policy-based redirect to the applications. Correct Answer
  2. Enable Cloud OnRamp for the branch sites.
  3. Configure IPsec to the cloud provider.
  4. Implement direct connect for site connectivity.

Community Votes

B
83%
A
17%

83% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the distinction between SD-WAN application-aware routing (Policy-Based Redirect) and cloud interconnect services (Cloud OnRamp).

Configuring policy-based redirect allows specific SaaS traffic to bypass the central hub and use local internet, optimizing performance while maintaining security policies. This page clarifies why BGP/Cloud OnRamp is not required for generic SaaS direct breakout.

Candidates often select Cloud OnRamp because it involves 'cloud' and 'SD-WAN', but it is designed for connecting to Oracle/AWS/Azure private clouds, not general public internet SaaS.

Community Discussion (4 comments)

kalulosu 👍 1 Selected: B
I think correct answer is B. By enabling Cloud OnRamp, traffic to specific cloud SaaS applications is routed directly to Internet access, while other Internet-facing traffic is routed through the normal path. This is the best way to leverage existing SD-WAN and cloud provider integration.
0d1b5b9 👍 1 Selected: B
I think "The customer wants to leverage its existing SD-WAN solution" is the key.
Redrum702 👍 1 Selected: A
Answer is A: o enable direct internet access for specific SaaS applications from remote branch sites while leveraging the existing SD-WAN solution, the appropriate action to take on the remote branch routers is: A. Define a policy-based redirect to the applications. Explanation: Policy-Based Redirect: This approach allows you to specify which traffic (in this case, traffic destined for specific SaaS applications) should be routed directly to the internet. By defining a policy that identifies these applications, the SD-WAN solution can handle the routing appropriately, ensuring that only the designated traffic bypasses the normal path.
crypto700 👍 3 Selected: B
I think the answer should be B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Policy-Based Redirect (PBR) is the mechanism in Cisco SD-WAN that allows administrators to define specific traffic flows (based on applications or destinations) and steer them over a specific transport link, such as a local broadband internet circuit. This meets the requirement of allowing direct internet access for specific SaaS apps while keeping other traffic on the usual path (likely the MPLS or encrypted IPsec tunnel to the data center).

Why the Other Options Are Wrong

Cloud OnRamp (B) is used to connect SD-WAN branches to specific IaaS providers like AWS, Azure, or OCI using VCN/VPC peering or transit gateways. It does not facilitate direct breakout to the public internet for arbitrary SaaS applications. IPsec (C) is a transport protocol, not a routing policy for breaking out specific traffic. Direct Connect (D) refers to AWS Dedicated Connections, which is an IaaS interconnect, not a branch SaaS optimization feature.

Community Comment Notes

The community majority voted for B, likely confusing 'Cloud OnRamp' with any cloud-related SD-WAN feature. One commenter noted that enabling Cloud OnRamp routes specific cloud traffic directly, but this applies to private cloud interconnects, not general SaaS. Another user correctly identified A, explaining that PBR specifies which traffic goes where, aligning with the 'specific SaaS' requirement.

Official Reference

Exam Strategy

When you see 'direct internet access' for specific apps in SD-WAN, think Policy-Based Redirect or Application-Aware Routing. Reserve Cloud OnRamp answers for questions mentioning AWS, Azure, OCI, or VPC/VCN integration.

Frequently Asked Questions

What is the difference between Policy-Based Redirect and Cloud OnRamp?

PBR steers traffic to local internet or specific tunnels based on app/dest. Cloud OnRamp connects branches to private IaaS clouds (AWS/Azure) via dedicated interconnects.

Can I use Cloud OnRamp for direct SaaS internet access?

No. Cloud OnRamp is for private cloud connectivity. For public SaaS apps breaking out locally, you must use Policy-Based Redirect or Local Breakout configurations.

Related Analysis

← Back to 400-007 Study Guide