nerdexam
Cisco

300-415 · Question #402

What are the two requirements for plug-and-play provisioning on Cisco IOS XE SD-WAN devices? (Choose two.)

The correct answer is D. The gateway router for the WAN Edge device must be able to reach ztp.viptela.com. E. The WAN Edge device must have a valid certificate. PnP provisioning for Cisco SD-WAN devices requires the WAN Edge to reach the ZTP server and possess a valid device certificate for authentication and secure communication.

WAN Edge Router Deployment

Question

What are the two requirements for plug-and-play provisioning on Cisco IOS XE SD-WAN devices? (Choose two.)

Options

  • ADevices at branch offices must be able to reach the Cisco SD-WAN vSmart controller at the headquarters site.
  • BThe gateway router for the WAN Edge device must be able to reach devicehelper.cisco.com.
  • CThe gateway router for the WAN Edge device must be able to reach public DNS servers.
  • DThe gateway router for the WAN Edge device must be able to reach ztp.viptela.com.
  • EThe WAN Edge device must have a valid certificate.

How the community answered

(40 responses)
  • B
    3% (1)
  • C
    3% (1)
  • D
    95% (38)

Why each option

PnP provisioning for Cisco SD-WAN devices requires the WAN Edge to reach the ZTP server and possess a valid device certificate for authentication and secure communication.

ADevices at branch offices must be able to reach the Cisco SD-WAN vSmart controller at the headquarters site.

While vSmart connectivity is crucial for a fully provisioned SD-WAN fabric, it's not a prerequisite for the initial PnP provisioning process itself; PnP first establishes connectivity to vBond.

BThe gateway router for the WAN Edge device must be able to reach devicehelper.cisco.com.

devicehelper.cisco.com is not directly involved in the standard PnP process for Cisco SD-WAN devices to discover the vBond or retrieve initial configurations.

CThe gateway router for the WAN Edge device must be able to reach public DNS servers.

While DNS resolution is generally required for internet access, the specific requirement for PnP is to resolve ztp.viptela.com, which implies access to any functional DNS, not specifically "public DNS servers" as a distinct requirement.

DThe gateway router for the WAN Edge device must be able to reach ztp.viptela.com.Correct

The WAN Edge device needs to reach ztp.viptela.com (or ztp.cisco.com) to discover the vBond orchestrator's IP address and initiate the zero-touch provisioning process.

EThe WAN Edge device must have a valid certificate.Correct

A valid device certificate, typically pre-installed or obtained via ZTP, is essential for the WAN Edge device to authenticate itself with the Cisco SD-WAN control plane components (vBond, vManage, vSmart).

Concept tested: Cisco SD-WAN ZTP/PnP requirements

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-xe-gs-book_chapter_010.html

Topics

#SD-WAN Provisioning#Zero Touch Provisioning#WAN Edge Deployment#Device Authentication

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice