Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Palo Alto Networks SD-WAN-Engineer Exam - Topic 2 Question 9 Discussion

Where is route leaking configured between VRFs?
D) VRF profile
A) VRF definition
B) BGP peer
C) Site configuration

Palo Alto Networks SD-WAN-Engineer Exam - Topic 2 Question 9 Discussion

Actual exam question for Palo Alto Networks's SD-WAN-Engineer exam
Question #: 9
Topic #: 2
[All SD-WAN-Engineer Questions]

Where is route leaking configured between VRFs?

Show Suggested Answer Hide Answer
Suggested Answer: D

In the Prisma SD-WAN solution, multi-tenancy and network isolation are achieved through the use of Virtual Routing and Forwarding (VRF) instances. However, there are many operational scenarios---such as providing shared access to a common service (e.g., DNS, NTP) or a central Internet gateway---where traffic must transition between these isolated routing domains. This process is known as route leaking.

In the Prisma SD-WAN management interface, route leaking is specifically configured within the VRF Profile. Unlike traditional CLI-based routers where route leaking might be configured under a global routing table or individual VRF definitions via import/export targets, Prisma SD-WAN utilizes a profile-based approach to ensure scalability and consistency across multiple sites. A VRF Profile acts as a template that defines the routing behavior for specific VRFs across the fabric.

When an administrator navigates to the VRF Profile settings, they can define 'Leaking Rules.' These rules specify the 'From VRF' (source) and 'To VRF' (destination) parameters, along with the specific prefixes or default routes that should be shared. By placing this configuration within the VRF Profile rather than a site-specific configuration, Palo Alto Networks allows for a 'configure once, apply many' workflow. Once the VRF Profile is updated with the leaking rules, any ION device associated with that profile will automatically update its local routing table to allow the specified inter-VRF communication. This centralized orchestration simplifies the management of complex segmentation requirements in large-scale SD-WAN deployments.


Contribute your Thoughts:

0/2000 characters
Chuck
2 days ago
I think it's A) VRF definition. Makes sense to configure there.
upvoted 0 times
...
Maile
7 days ago
Are you sure it's not in the BGP peer settings?
upvoted 0 times
...
Lashon
12 days ago
Wait, I didn't know it was in the VRF definition!
upvoted 0 times
...
Tamar
17 days ago
I thought it was B, but A makes sense too.
upvoted 0 times
...
Melda
2 months ago
Totally agree, A is the right answer!
upvoted 0 times
...
Glen
2 months ago
It's configured in the VRF definition.
upvoted 0 times
...
Nadine
3 months ago
I feel like site configuration might be relevant, but it seems more like a general setup rather than specific to route leaking.
upvoted 0 times
...
Julene
3 months ago
I practiced a similar question where VRF profiles were mentioned, but I don’t think that’s the right answer here.
upvoted 0 times
...
Edna
3 months ago
I remember something about BGP peers being involved in route leaking, but I can't recall the specifics.
upvoted 0 times
...
Weldon
4 months ago
I think route leaking is configured in the VRF definition, but I’m not entirely sure.
upvoted 0 times
...

Save Cancel