In Cisco Catalyst SD-WAN cloud integration, when the requirement is:
Automatically discovering AWSVPCs
Automatically identifying AWSservices
Allowing the user to choose whichprivate SD-WAN networkconnects to the cloud
UsingAWS credentials(Access Key / Secret Key) for automatic provisioning
…the Cisco-supported mechanism is theCisco SD-WAN Transit VPC solution.
Why Transit VPC is the correct answer:
It is specifically designed to integrateCisco SD-WANwith AWS environments.
Uses AWS APIs and user credentials to automatically discover:
VPC IDs
Subnets
Regions
Routing tables
Automatically deploys and configures CSR1000v or Catalyst 8000V routers into the VPC.
Provides a centralized “hub” in AWS to interconnect multiple SD-WAN sites.
Enables the user to choose which SD-WAN segments connect to which VPCs.
This matches the requirement ofautomatic cloud resource identification based on user credentials.
Why the other options are incorrect
A. AWS Direct Connect
This is a physical/private Layer 2 cloud connection.
It doesnotauto-discover VPCs or integrate through credentials.
It does not provide automated SD-WAN service provisioning.
C. IPsec VPN
Works for connectivity but ismanual, not automated.
Does not identify AWS cloud resources via credentials.
D. Segment routing
A transport technology used inside SP networks, irrelevant to AWS API-based VPC discovery.
Thus, onlyTransit VPCprovides automatic AWS cloud discovery and integration with SD-WAN.