nerdexam
Broadcom-VMware

5V0-42.21 · Question #16

The VMware SD-WAN solution is comprised of Orchestrator, Gateway, and Edge. The architecture ensures separation and secure communication between the management, control, and data plane of the…

The correct answer is D. Traffic between VMware SD-WAN Edges and from VMware SD-WAN Edges to VMware SD-WAN. Option D correctly captures that data plane traffic - both Edge-to-Edge and Edge-to-Gateway - is encrypted using IPsec/AES, which is the defining characteristic of how VMware SD-WAN secures the data plane independently from the management and control planes. This separation is…

SD-WAN Architecture and Technologies

Question

The VMware SD-WAN solution is comprised of Orchestrator, Gateway, and Edge. The architecture ensures separation and secure communication between the management, control, and data plane of the solution. The management plane consists of the VMware SD-WAN Orchestrator, and the control plane is comprised of the VMware SD-WAN Gateway/Controller. Which statement correctly describes this situation?

Options

  • AVMware SD-WAN Edges/Gateways establishes a Transport Layer Security (TLS) 1 2 encrypted
  • BTo make the entire solution to work property, TCP port 443 and HOP port 500 and UDP port 4500
  • CThere is impact on data plane when the Edge loses connectivity to the management plane. The
  • DTraffic between VMware SD-WAN Edges and from VMware SD-WAN Edges to VMware SD-WAN

How the community answered

(58 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    5% (3)
  • D
    91% (53)

Explanation

Option D correctly captures that data plane traffic - both Edge-to-Edge and Edge-to-Gateway - is encrypted using IPsec/AES, which is the defining characteristic of how VMware SD-WAN secures the data plane independently from the management and control planes. This separation is fundamental to the architecture: the data plane continues forwarding traffic even if the Edge loses contact with the Orchestrator or Gateway.

Option C is a common trap and is wrong - the data plane is not impacted by loss of management plane connectivity; that resilience is precisely why the planes are separated. Option A is misleading because TLS 1.2 applies to management/control plane communications (Edge-to-Orchestrator), not the data plane tunnels themselves. Option B is a distractor focused on firewall port requirements (443, 500, 4500), which is a supporting detail about network prerequisites, not a statement about the architectural design.

Memory tip: Think "Data plane = Doesn't need the others to survive." SD-WAN separates the planes so that a management outage never drops your traffic - the IPsec tunnels between Edges and Gateways keep running regardless.

Topics

#VMware SD-WAN Architecture#Management & Control Planes#Secure Communication/TLS#Component Separation

Community Discussion

No community discussion yet for this question.

Full 5V0-42.21 Practice