A police records bureau needs shared directory services reachable from multiple service VPNs at the hub without merging those VRFs site-wide. Which approach fits Cisco SD-WAN intent?
Select an answer to reveal the explanation.
Short Explanation
Think of the hub as a carefully watched door between locked rooms. You don’t knock the walls down—you leak just the shared-services prefixes the rooms actually need. That’s controlled inter-VPN route sharing, not a full merge.
Full Explanation
Cisco SD-WAN supports controlled route leaking between service VPNs so shared services can be reached without collapsing segmentation everywhere. Intent-based policy at the hub advertises only the required prefixes across VPN boundaries. Placing departmental routes in VPN 0 or bridging overlays defeats the transport-versus-service model and weakens isolation.