nerdexam
CiscoCisco

350-401 · Question #406

350-401 Question #406: Real Exam Question with Answer & Explanation

The correct answer is A: vBond. vBond as STUN Server vBond (A) is correct because it is specifically designed to act as a STUN (Session Traversal Utilities for NAT) server in the Cisco SD-WAN architecture. During the Edge device onboarding process, vBond helps WAN Edge routers discover their own public IP addre

Submitted by akirajp· Mar 6, 2026Architecture

Question

Which controller is capable of acting as a STUN server during the onboarding process of Edge devices?

Options

  • AvBond
  • BvSmart
  • CvManage
  • DPNP server

Explanation

vBond as STUN Server

vBond (A) is correct because it is specifically designed to act as a STUN (Session Traversal Utilities for NAT) server in the Cisco SD-WAN architecture. During the Edge device onboarding process, vBond helps WAN Edge routers discover their own public IP addresses and ports when they are behind NAT devices, enabling them to establish secure control plane connections with vSmart and vManage.

vSmart (B) is wrong because its role is to distribute routing and policy information to WAN Edge devices via the OMP protocol - it does not perform NAT traversal functions. vManage (C) is the centralized management and orchestration platform responsible for configuration and monitoring, not NAT traversal. PNP Server (D) is a Cisco plug-and-play provisioning tool used for Zero Touch Provisioning (ZTP) of devices, but it is not part of the SD-WAN NAT traversal or onboarding orchestration process in the same capacity as vBond.

🧠 Memory Tip: Think "vBond = Bridge over NAT" - vBond bonds devices together by helping them traverse NAT, just like a bridge connects two sides. The "B" in vBond can remind you of both Bridge and Behind-NAT traversal.

Topics

#Cisco SD-WAN#vBond#STUN server#Device onboarding

Community Discussion

No community discussion yet for this question.

Full 350-401 PracticeBrowse All 350-401 Questions