nerdexam
HP

HPE7-A02 · Question #71

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub- spoke VPN between branch gateways (BGWs) at 1164 site and VPNCs at multiple data centers. What is part of the…

The correct answer is C. In BGWs' groups, select the VPNCs to which to connect in a DC preference list. Option C is correct because in an Aruba Central SD-WAN hub-spoke topology, branch gateways (BGWs) are the spokes that initiate tunnels outward to the hub VPNCs. Logically, the spoke-side configuration is where you define which hubs to connect to - admins configure a DC…

Implementing Advanced Security Features

Question

A company is using HPE Aruba Networking Central SD-WAN Orchestrator to establish a hub- spoke VPN between branch gateways (BGWs) at 1164 site and VPNCs at multiple data centers. What is part of the configuration that admins need to complete?

Options

  • AIn VPNCs' groups, establish VPN pools to control which branches connect to which VPNCs.
  • BIn BGWs' and VPNCs' groups, create default IKE policies for the SD-WAN Orchestrator to use.
  • CIn BGWs' groups, select the VPNCs to which to connect in a DC preference list.
  • DAt the global level, create default IPsec policies for the SD-WAN Orchestrator to use.

How the community answered

(43 responses)
  • A
    5% (2)
  • B
    9% (4)
  • C
    84% (36)
  • D
    2% (1)

Explanation

Option C is correct because in an Aruba Central SD-WAN hub-spoke topology, branch gateways (BGWs) are the spokes that initiate tunnels outward to the hub VPNCs. Logically, the spoke-side configuration is where you define which hubs to connect to - admins configure a DC preference list within the BGW group to specify which VPNCs each branch should establish tunnels with, and in what priority order.

Why the distractors are wrong:

  • A is wrong because VPN pools are not how Central SD-WAN controls branch-to-VPNC mapping. You don't configure "pools" on the VPNC side to dictate which branches connect.
  • B is wrong because IKE policies do not need to be manually created in both BGW and VPNC groups - the orchestrator uses system defaults, and this is not a required admin step for establishing the VPN.
  • D is wrong because IPsec policies at the global level are also handled by defaults in the orchestrator; manually creating them is not part of the required hub-spoke setup workflow.

Memory tip: Think "spokes choose their hub." The BGW (spoke/branch) group is where you configure the preference list of VPNCs (hubs/DCs) to connect to - branches reach out, so the outbound configuration lives on the branch side.

Topics

#SD-WAN#hub-spoke VPN#BGW configuration#VPNC

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice