mediumMultiple Choice
350-401 Practice Question: Consider the following SD-WAN configuration…
Consider the following SD-WAN configuration snippet on a Cisco IOS-XE router:
interface GigabitEthernet0/0/1 ip address 10.1.1.1 255.255.255.0
tunnel-interface
encapsulation ipsec
color biz-internet
no allow-service bgp
allow-service dhcp allow-service dns allow-service icmp !
What is the effect of this configuration?
⚠ Common exam trap
Cisco often tests the misconception that 'no allow-service bgp' is invalid or that the tunnel-interface configuration only applies to loopback interfaces, when in fact it is a valid command applied to physical interfaces to filter control-plane traffic per transport color.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The interface is configured as an SD-WAN tunnel interface with color biz-internet, allowing DHCP, DNS, and ICMP traffic but blocking BGP.
The configuration applies to a GigabitEthernet interface that is placed into SD-WAN tunnel mode using the 'tunnel-interface' command. The 'color biz-internet' assigns the transport color, and the 'allow-service' and 'no allow-service' commands explicitly control which control-plane services are permitted over the tunnel. DHCP, DNS, and ICMP are allowed, while BGP is explicitly denied, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The interface is configured as an SD-WAN tunnel interface with color biz-internet, allowing DHCP, DNS, and ICMP traffic but blocking BGP.
Why this is correct
This is correct because the `tunnel-interface` command provisions the physical GigabitEthernet interface as an SD-WAN transport tunnel, and the `color biz-internet` attribute designates the WAN transport class. The `allow-service` statement explicitly permits DHCP, DNS, and ICMP while the `no allow-service bgp` line denies BGP, so the interface only carries the listed services and not BGP.
- ✗
The interface is configured as a standard WAN interface with IPsec encryption, allowing all services including BGP.
Why it's wrong here
This is incorrect because `tunnel-interface` is an SD-WAN-specific configuration that creates a secure tunnel with IPsec encapsulation, not a standard WAN interface. Moreover, the `no allow-service bgp` command explicitly blocks BGP, contradicting the claim that all services are allowed; thus the interface is not a plain IPsec WAN and BGP is specifically denied.
- ✗
The configuration enables the interface as a loopback tunnel for OMP traffic only, blocking all other services.
Why it's wrong here
This is incorrect because the interface is a physical GigabitEthernet interface, not a loopback interface, and tunnel-interface does not create a loopback. Additionally, the configuration allows DHCP, DNS, and ICMP rather than blocking all other services, and OMP traffic is carried over the tunnel's control plane (DTLS/tLS), not exclusively as the sole service.
- ✗
The interface is configured for SD-WAN with color biz-internet, but the 'no allow-service bgp' command is invalid on a tunnel interface.
Why it's wrong here
This is incorrect because `no allow-service bgp` is a valid and commonly used command under a `tunnel-interface`; it explicitly removes BGP from the permitted service list on that tunnel. The command is not invalid—it simply ensures BGP is not transported over the SD-WAN tunnel, while other services like DHCP, DNS, and ICMP remain allowed.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.