Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks SD-WAN-Engineer Exam - Topic 2 Question 10 Discussion

Actual exam question for Palo Alto Networks's SD-WAN-Engineer exam
Question #: 10
Topic #: 2
[All SD-WAN-Engineer Questions]

When deploying a branch gateway, secure fabric VPN tunnels are automatically established between which two site types? (Choose two.)

Show Suggested Answer Hide Answer
Suggested Answer: B, C

In the Prisma SD-WAN (Instant-On Network) architecture, the 'Secure Fabric' is a key feature that simplifies VPN orchestration through automation. When an ION device is deployed at a site and associated with a specific role, the Prisma SD-WAN Controller automatically manages the establishment of encrypted VPN tunnels without requiring manual IPsec configuration.

The most fundamental tunnel type is Branch gateway to data center (Option B). By default, the system follows a hub-and-spoke model where every branch ION device automatically attempts to build secure tunnels to all available Data Center clusters within its domain. This ensures that branch locations have immediate, redundant connectivity to centralized corporate resources and applications as soon as they are brought online.

Additionally, Prisma SD-WAN supports automated Branch gateway to branch gateway connectivity (Option C). Unlike traditional architectures that backhaul all traffic through a central hub, the Prisma SD-WAN fabric can dynamically establish 'spoke-to-spoke' tunnels between branch gateways to facilitate direct communication. This is particularly useful for latency-sensitive applications like Voice over IP (VoIP) or video conferencing. While this can be configured as a 'full mesh' where all sites build tunnels to all other sites, the controller intelligently manages these connections based on the defined site roles and domain configurations to optimize resource usage and performance. Options A and D are incorrect because the fabric orchestration logic is primarily focused on the functional roles of the gateways (Branch vs. Data Center) rather than 'domains' in the context of tunnel initiation.


Contribute your Thoughts:

0/2000 characters
Barney
2 days ago
I remember practicing a similar question, and I think it was about branch to branch gateways in the same domain. That might be one of the answers.
upvoted 0 times
...
France
7 days ago
I think the secure fabric VPN tunnels are established between the branch gateway and the data center, but I'm not entirely sure about the second option.
upvoted 0 times
...

Save Cancel