ENSDWI Exam QuestionsBrowse all questions from this exam

ENSDWI Exam - Question 8


A network administrator is bringing up one WAN Edge router for branch connectivity. Which types of tunnels form when the WAN edge router connects to the

Cisco SD-WAN fabric?

Show Answer
Correct Answer: D

When a WAN edge router connects to the Cisco SD-WAN fabric, it establishes a DTLS or TLS tunnel with the vSmart controller to ensure secure and reliable control plane connections. Additionally, the WAN edge router forms IPsec tunnels with other WAN edge routers to secure the data plane traffic passing between the branches. Hence, DTLS or TLS tunnels are used for control plane communication with controllers like vSmart, while IPsec tunnels are used for data plane communication among WAN edge routers.

Discussion

8 comments
Sign in to comment
HAMPI
Sep 16, 2022

D is the correct answer. 1. VBOND will make only DTLS connection, TLS connection will not happen between vBond and vEdge. 2. vBond connection is temporary 3. vEdges will make IPSec tunnels over data plane

khandaOption: D
Nov 11, 2022

vBond will only make a DTLS connection.

CCNPWILL
Oct 25, 2021

I believe this is correct a well.

ramjam
Dec 11, 2021

Correct. https://sdwan-docs.cisco.com/Product_Documentation/Software_Features/SD-WAN_Release_16.3/05Security/01Security_Overview

serieus
Feb 13, 2022

Technically C is also correct, but the DTLS tunnel to the vBond is torn down after the Edge receives the vManage & vSmart IP's. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/cisco-sd-wan-overlay-network-bringup.html

serieus
Feb 13, 2022

Have to correct myself. The vBond is locked to DTLS only so C is NOT correct.

khanda
Aug 24, 2022

C is the correct answer, the minimal config on the Edge device contains the vBond IP or DNS name, so first comms would be to the vBond through TLS/DTLS tunnel connection. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/cisco-sd-wan-overlay-network-bringup.html

khanda
Nov 4, 2022

Correct answer is D. vBond do not utilise TLS but DTLS.

akin5
Aug 28, 2022

dear Team what is the solution to this Q An MPLS connection on R2 must extend to R1 Users behind R1 must have dual connectivity for data traffic Which configuration provides R1 control connectivity over the MPLS connection?

Mfanelo
Oct 2, 2024

I go with D.