nerdexam
Broadcom-VMware

5V0-42.21 · Question #50

Which role(s) must be enable under Gateway configuration page to allow a VMware SD-WAN Gateway to build IPsec tunnels to non-VM SD-WAN?

The correct answer is B. Control Plane + Data Plane + Partner Gateway. Option B is correct because building IPsec tunnels to non-VMware SD-WAN devices (third-party or partner networks) requires all three roles: Control Plane (for orchestration and routing), Data Plane (to actually forward/encrypt traffic), and Partner Gateway (which specifically…

SD-WAN Deployment and Configuration

Question

Which role(s) must be enable under Gateway configuration page to allow a VMware SD-WAN Gateway to build IPsec tunnels to non-VM SD-WAN?

Options

  • AControl Plane
  • BControl Plane + Data Plane + Partner Gateway
  • CControl Plane + Secure VPN Gateway
  • DControl Plane + Data Plane + Secure VPN Gateway

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    74% (17)
  • C
    17% (4)
  • D
    4% (1)

Explanation

Option B is correct because building IPsec tunnels to non-VMware SD-WAN devices (third-party or partner networks) requires all three roles: Control Plane (for orchestration and routing), Data Plane (to actually forward/encrypt traffic), and Partner Gateway (which specifically enables the gateway to terminate IPsec tunnels from non-SD-WAN endpoints like physical routers or competitor devices).

  • A (Control Plane only) is wrong - the control plane alone handles signaling and topology, but without the data plane there's no actual packet forwarding, and without Partner Gateway there's no non-SD-WAN IPsec termination capability.
  • C (Control Plane + Secure VPN Gateway) is wrong - Secure VPN Gateway is used for securing internal SD-WAN traffic flows, not for interoperating with external, non-VMware devices.
  • D (Control Plane + Data Plane + Secure VPN Gateway) is a convincing distractor but swaps "Partner Gateway" for "Secure VPN Gateway"; the Partner role is the key differentiator for third-party IPsec peers.

Memory tip: Think "Partner Gateway = Peer with non-VMware." Any time the question mentions tunnels to non-SD-WAN or third-party endpoints, "Partner Gateway" must be in the answer - and it always comes bundled with both Control and Data Plane since a gateway needs all three layers to function.

Topics

#Gateway Configuration#IPsec Tunneling#Partner Gateway#Role-Based Setup

Community Discussion

No community discussion yet for this question.

Full 5V0-42.21 Practice