nerdexam
Cisco

300-415 · Question #267

Refer to the exhibit. vManage and vBond have an issue establishing a connection to vSmart. Which two actions does the administrator take to fix the issue? (Choose two.)

The correct answer is C. Install the certificate received from the certificate server. E. Request a certificate from the certificate server based on the CSR for the vSmart. If vManage and vBond cannot connect to vSmart, a common issue is certificate-related, requiring the administrator to request a CSR from vSmart, obtain a certificate from the CA, and then install it on the vSmart controller.

Controller Deployment

Question

Refer to the exhibit. vManage and vBond have an issue establishing a connection to vSmart. Which two actions does the administrator take to fix the issue? (Choose two.)

Options

  • AReconfigure the vSmart from CLI with the proper Hostname & System IP.
  • BManually resync vManage and vBond.
  • CInstall the certificate received from the certificate server.
  • DDelete and re-add vSmart. Click Generate and validate CSR.
  • ERequest a certificate from the certificate server based on the CSR for the vSmart.

How the community answered

(62 responses)
  • A
    8% (5)
  • B
    15% (9)
  • C
    73% (45)
  • D
    5% (3)

Why each option

If vManage and vBond cannot connect to vSmart, a common issue is certificate-related, requiring the administrator to request a CSR from vSmart, obtain a certificate from the CA, and then install it on the vSmart controller.

AReconfigure the vSmart from CLI with the proper Hostname & System IP.

While hostname and system IP are critical, reconfiguring them from the CLI is usually done during initial setup; if the issue is a connection to vSmart from other controllers, certificates are a more common problem once basic addressing is in place.

BManually resync vManage and vBond.

Manually resyncing vManage and vBond is not directly related to a vSmart connection issue and would not resolve a certificate problem on vSmart.

CInstall the certificate received from the certificate server.Correct

Once a certificate signing request (CSR) for the vSmart controller has been submitted to a certificate authority (CA) and the signed certificate has been received, it must be installed on the vSmart controller to establish trust and allow control plane connections.

DDelete and re-add vSmart. Click Generate and validate CSR.

Deleting and re-adding vSmart is a drastic step and might be necessary if the initial setup was completely flawed, but the problem description points more towards a certificate issue, which choices C and E directly address.

ERequest a certificate from the certificate server based on the CSR for the vSmart.Correct

For secure communication, the vSmart controller requires a valid device certificate. This involves generating a Certificate Signing Request (CSR) on the vSmart and then submitting it to a trusted Certificate Authority (CA) to get a signed certificate.

Concept tested: SD-WAN controller certificate management for trust

Source: https://www.cisco.com/c/en/us/td/docs/sdwan/sd-wan-release-20-x/install-and-upgrade/vManage-NMS/vmanage-vbond-vsmart-installation-guide.html

Topics

#SD-WAN Control Plane#Controller Certificates#Controller Connectivity#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice