300-415 · Question #164
Which secure tunnel type should be used to connect one WAN Edge router to other WAN Edge routers?
The correct answer is D. TLS. WAN Edge routers primarily use IPsec for data plane tunnels, but establish control plane connections with vSmart controllers using DTLS or TLS to build the overlay.
Question
Exhibit
Options
- ADTLS
- BSSL VPN
- CIPSec
- DTLS
How the community answered
(31 responses)- A3% (1)
- B13% (4)
- C3% (1)
- D81% (25)
Why each option
WAN Edge routers primarily use IPsec for data plane tunnels, but establish control plane connections with vSmart controllers using DTLS or TLS to build the overlay.
DTLS is the default protocol for control plane connections between WAN Edge routers and vSmart controllers, but TLS is also a valid alternative.
SSL VPNs are typically used for remote user access to a network, not for forming the core site-to-site overlay network between WAN Edge routers in Cisco SD-WAN.
IPsec is used for the data plane tunnels between WAN Edge routers to encrypt user traffic, not for the underlying control plane connections that establish the overlay itself.
TLS can be used as the secure tunnel type for establishing control plane connections between WAN Edge routers and vSmart controllers, which are fundamental for building the overlay network that logically connects WAN Edge routers. While DTLS is the default for control, TLS is an alternative when TCP is preferred.
Concept tested: SD-WAN secure tunnel types and planes
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-overlay-network-components-and-functions.html
Topics
Community Discussion
No community discussion yet for this question.
