300-415 · Question #107
Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two)
The correct answer is A. Generate a CSR manually within vManage server E. Install the certificate received from the CA server manually on the vManage. For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.
Question
Options
- AGenerate a CSR manually within vManage server
- BGenerate a CSR manually on the WAN Edge
- CRequest a certificate manually from the Enterprise CA server
- DInstall the certificate received from the CA server manually on the WAN Edge
- EInstall the certificate received from the CA server manually on the vManage
How the community answered
(16 responses)- A75% (12)
- B6% (1)
- C13% (2)
- D6% (1)
Why each option
For WAN Edges to register with controllers using certificates, the vManage controller must first establish its own certificate identity and trust chain, which is a foundational step for the entire SD-WAN fabric's security.
Generating a Certificate Signing Request (CSR) within the vManage server is the initial step for vManage to obtain its own certificate from an Enterprise CA, establishing its identity as a trusted orchestrator.
Generating a CSR on the WAN Edge is part of the individual WAN Edge's certificate process, but not a primary configuration action needed on the *controllers* to prepare for registration.
Requesting a certificate manually from the Enterprise CA server is an action performed on the CA, not a configuration step on the SD-WAN components themselves.
Installing the certificate on the WAN Edge is necessary for the WAN Edge to present its identity, but the question asks for configurations to get WAN Edges registered *with the controllers*, emphasizing the controllers' readiness.
Installing the certificate received from the CA server manually on vManage is crucial, as it enables vManage to secure its own control connections and act as a trusted entity that can validate and register WAN Edges within the SD-WAN overlay.
Concept tested: SD-WAN controller certificate management
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/m-sdwan-basic-config.html#Cisco_Concept.dita_b5b5c9b4-b903-49d7-83d7-e070d6a2a514
Topics
Community Discussion
No community discussion yet for this question.