SDWAN networks capitalize the usage of broadband Internet links over traditional MPLS links to offer more cost benefits to enterprise customers. However, due to the insecure nature of the public Internet, it is mandatory to use encryption of traffic between any two SDWAN edge devices installed behind NAT gateways.
Which overlay method can provide optimal transport over unreliable underlay networks that are behind NAT gateways?
Answer(s): C
Explanation:
-DTLS (Datagram Transport Layer Security) is a secure transport protocol that can be used to encrypt datagrams. However, it is not as widely deployed as IPsec.
-TLS (Transport Layer Security) is a secure transport protocol that can be used to encrypt data between two hosts. However, it is not as well-suited for use over unreliable underlay networks as IPsec.
-GRE (Generic Routing Encapsulation) is a tunneling protocol that can be used to encapsulate traffic between two hosts. However, it does not provide any encryption, so it is not suitable for use over insecure underlay networks.
-IPsec (Internet Protocol Security) is a secure tunneling protocol that can be used to encapsulate traffic between two hosts. It is well-suited for use over insecure underlay networks, as it provides encryption and authentication.
Here are some additional details about IPsec:
-IPsec is a mature and widely deployed protocol.
-IPsec provides strong encryption and authentication.
-IPsec can be used to encapsulate traffic between two hosts or between two networks.
-
Reveal Solution Next Question