300-415 · Question #19
Which component of the Cisco SD-WAN control plane architecture should be located in a public Internet address space and facilitates NAT-traversal?
The correct answer is C. vBond. The vBond orchestrator must reside on a public IP address because it is the first point of contact for all SD-WAN devices and must be reachable across NAT boundaries to facilitate device onboarding.
Question
Options
- AWAN Edge
- BvSmart
- CvBond
- DvManage
How the community answered
(34 responses)- A3% (1)
- B3% (1)
- C88% (30)
- D6% (2)
Why each option
The vBond orchestrator must reside on a public IP address because it is the first point of contact for all SD-WAN devices and must be reachable across NAT boundaries to facilitate device onboarding.
WAN Edge routers are the devices that sit behind NAT and rely on vBond to traverse it - they do not need a public IP address in the architecture.
vSmart controllers exchange OMP sessions with WAN Edges but do not need to be publicly addressed, as their connectivity can be established after vBond facilitates initial NAT traversal.
vBond is the only SD-WAN component mandated to have a publicly routable IP address because it authenticates new WAN Edge routers and controllers as they come online, and then helps them discover each other across NAT - a process that requires vBond itself to be reachable from any transport network. It uses STUN-like mechanisms to identify the public IP and port mappings of devices behind NAT, enabling hole-punching for subsequent direct tunnel establishment.
vManage handles management plane functions and does not need a public IP address specifically for NAT traversal - its accessibility depends on the operator's management network design.
Concept tested: Cisco SD-WAN vBond public IP NAT traversal role
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/system-overview.html
Topics
Community Discussion
No community discussion yet for this question.