An administrator is troubleshooting an SD-WAN rule that is not matching traffic as expected. The rule is configured with a source address of 'all', destination '10.0.0.0/24', and service 'HTTP'. The rule is placed after a rule that matches all traffic to '10.0.0.0/24' with service 'ALL'. The administrator notices that HTTP traffic to 10.0.0.0/24 is being handled by the first rule. What is the most likely cause?
SD-WAN rules are evaluated sequentially from top to bottom. The first rule matches all services, including HTTP, so it captures the traffic before the more specific rule is evaluated. To fix this, the administrator should reorder the rules so that the HTTP-specific rule is above the generic rule.
Why this answer
SD-WAN rules are processed in the order they are listed, and the first rule that matches the traffic is used. In this case, the rule with service 'ALL' matches HTTP traffic before the HTTP-specific rule is evaluated. The solution is to move the HTTP rule above the generic rule.
Exam trap
The trap here is assuming that SD-WAN rules use a most-specific-match logic like firewall policies, when in fact they are order-dependent.