300-415 · Question #267
Refer to the exhibit. vManage and vBond have an issue establishing a connection to vSmart. Which two actions does the administrator take to fix the issue? (Choose two.)
The correct answer is C. Install the certificate received from the certificate server. E. Request a certificate from the certificate server based on the CSR for the vSmart. If vManage and vBond cannot connect to vSmart, a common issue is certificate-related, requiring the administrator to request a CSR from vSmart, obtain a certificate from the CA, and then install it on the vSmart controller.
Question
Options
- AReconfigure the vSmart from CLI with the proper Hostname & System IP.
- BManually resync vManage and vBond.
- CInstall the certificate received from the certificate server.
- DDelete and re-add vSmart. Click Generate and validate CSR.
- ERequest a certificate from the certificate server based on the CSR for the vSmart.
How the community answered
(62 responses)- A8% (5)
- B15% (9)
- C73% (45)
- D5% (3)
Why each option
If vManage and vBond cannot connect to vSmart, a common issue is certificate-related, requiring the administrator to request a CSR from vSmart, obtain a certificate from the CA, and then install it on the vSmart controller.
While hostname and system IP are critical, reconfiguring them from the CLI is usually done during initial setup; if the issue is a connection to vSmart from other controllers, certificates are a more common problem once basic addressing is in place.
Manually resyncing vManage and vBond is not directly related to a vSmart connection issue and would not resolve a certificate problem on vSmart.
Once a certificate signing request (CSR) for the vSmart controller has been submitted to a certificate authority (CA) and the signed certificate has been received, it must be installed on the vSmart controller to establish trust and allow control plane connections.
Deleting and re-adding vSmart is a drastic step and might be necessary if the initial setup was completely flawed, but the problem description points more towards a certificate issue, which choices C and E directly address.
For secure communication, the vSmart controller requires a valid device certificate. This involves generating a Certificate Signing Request (CSR) on the vSmart and then submitting it to a trusted Certificate Authority (CA) to get a signed certificate.
Concept tested: SD-WAN controller certificate management for trust
Source: https://www.cisco.com/c/en/us/td/docs/sdwan/sd-wan-release-20-x/install-and-upgrade/vManage-NMS/vmanage-vbond-vsmart-installation-guide.html
Topics
Community Discussion
No community discussion yet for this question.