ECMS Network Design, Deployment, and SD-WAN 1 — Questions and Answers
Question 1: What is the primary Meraki SD-WAN feature that allows administrators to define preferred WAN paths for specific applications based on performance?
- WAN load balancing
- SD-WAN policies with performance classes (Correct answer)
- Static default route with metric
- PBR using ACLs
Correct answer: SD-WAN policies with performance classes
Meraki SD-WAN performance classes allow administrators to define latency, jitter, and loss thresholds and automatically route specific application traffic to the best-performing WAN link.
Question 2: In a Meraki SD-WAN deployment, what is the role of the 'Hub' site in an Auto VPN topology?
- It provides internet breakout for all spoke sites
- It serves as a central aggregation point that spoke sites connect to for VPN and shared resource access (Correct answer)
- It manages firmware updates for all spoke devices
- It performs deep packet inspection on behalf of spoke devices
Correct answer: It serves as a central aggregation point that spoke sites connect to for VPN and shared resource access
The Hub site in Meraki Auto VPN serves as the central termination point for spoke-to-hub VPN tunnels, enabling spokes to access data center resources and shared services through the hub.
Question 3: When designing a Meraki network for 500 branch sites, what architectural approach does Cisco recommend for efficient management?
- Create one network per device for maximum isolation
- Use a template network (configuration template) applied to all branch networks (Correct answer)
- Manually configure each branch via CLI backup scripts
- Deploy a separate on-premises controller for branches
Correct answer: Use a template network (configuration template) applied to all branch networks
Meraki configuration templates allow administrators to define a master configuration applied to multiple branch networks, ensuring consistency and dramatically simplifying large-scale deployments.
Question 4: What Meraki feature enables branch sites to send internet-bound traffic directly to the internet rather than backhauling it through a hub data center?
- Internet traffic is always sent to the hub in Meraki
- Local internet breakout configured via SD-WAN traffic policies (Correct answer)
- MPLS replacement with dedicated VPN for internet traffic
- Content filtering must be disabled for local breakout
Correct answer: Local internet breakout configured via SD-WAN traffic policies
Meraki SD-WAN supports local internet breakout by configuring SD-WAN policies to route internet traffic directly out of the local WAN interface rather than through the Auto VPN tunnel to the hub.
Question 5: Which Meraki licensing model component is required for all managed devices to communicate with the Meraki cloud?
- Advanced Security License
- Enterprise License
- Base SD-WAN License
- A valid Meraki license for the specific product line (Correct answer)
Correct answer: A valid Meraki license for the specific product line
All Meraki hardware requires an active license for the device to be managed through the cloud; without a valid license the device will eventually lose management functionality.
Question 6: In Meraki SD-WAN design, what is 'WAN load balancing' and how does it differ from failover?
- Load balancing and failover are identical features with different names
- Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails (Correct answer)
- Load balancing uses BGP to distribute traffic; failover uses STP
- Load balancing requires a third-party appliance in addition to the MX
Correct answer: Load balancing distributes active traffic across both WAN links simultaneously, while failover only uses the secondary link when the primary fails
WAN load balancing actively distributes flow-level traffic across both uplinks to maximize available bandwidth, while failover keeps the secondary link idle until the primary fails.
What is the primary Meraki SD-WAN feature that allows administrators to define preferred WAN paths for specific applications based on performance?