300-415 · Question #446
Which Certificate of Authority (CA) option is used when configuring a TLS proxy in the Cisco Catalyst SD-WAN environment?
The correct answer is A. SD-WAN Manager as CA. In a Cisco Catalyst SD-WAN environment, the SD-WAN Manager (vManage) serves as the Certificate Authority (CA) for generating certificates, including those used by a TLS proxy.
Question
Exhibit
Options
- ASD-WAN Manager as CA
- BSD-WAN Controller as CA
- CvController as CA
- DWAN Edge as CA
How the community answered
(39 responses)- A90% (35)
- B3% (1)
- C3% (1)
- D5% (2)
Why each option
In a Cisco Catalyst SD-WAN environment, the SD-WAN Manager (vManage) serves as the Certificate Authority (CA) for generating certificates, including those used by a TLS proxy.
In the Cisco Catalyst SD-WAN architecture, the SD-WAN Manager (vManage) typically functions as the Certificate Authority (CA) to issue and manage certificates for all fabric devices, including those required for TLS proxy functionality.
The SD-WAN Controller (vSmart) is responsible for the control plane and routing policies, not for acting as a Certificate Authority.
"vController" is synonymous with vSmart (SD-WAN Controller), which does not serve as a Certificate Authority.
A WAN Edge device is a data plane component that processes traffic and enforces policies, but it does not function as a Certificate Authority within the SD-WAN fabric.
Concept tested: Cisco SD-WAN Certificate Authority role
Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-cr-book/sdwan-security-features.html
Topics
Community Discussion
No community discussion yet for this question.
