mediumMultiple Choice
CCNP Practice Question: Examine the following SD-WAN configuration on a…
Examine the following SD-WAN configuration on a Cisco vEdge router:
vpn 0
interface ge0/0 ip address 10.0.0.1/24
tunnel-interface
encapsulation ipsec
color public-internet allow-service all !
interface ge0/1 ip address 10.0.0.2/24
tunnel-interface
encapsulation ipsec
color 3g allow-service all !
Which statement is correct?
⚠ Common exam trap
Cisco often tests the misconception that VPN 0 is a service VPN or that multiple tunnel interfaces in the same VPN are invalid, but the key is remembering that VPN 0 is strictly the transport underlay and supports multiple colored interfaces for control-plane connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Both interfaces are in VPN 0, which is the transport VPN, and they will establish tunnels with the vSmart controller.
VPN 0 is the transport VPN in Cisco SD-WAN, used exclusively for underlay network connectivity and control plane traffic. The two interfaces ge0/0 and ge0/1 are configured as tunnel interfaces with IPsec encapsulation and different colors (public-internet and 3g), which allows them to establish secure DTLS/TLS tunnels to the vSmart controller for orchestration and policy distribution. This is correct because transport VPN interfaces are designed to carry overlay control traffic, not customer data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Both interfaces are in VPN 0, which is the transport VPN, and they will establish tunnels with the vSmart controller.
Why this is correct
In Cisco SD-WAN, VPN 0 is the dedicated transport VPN that carries underlay connectivity and control plane traffic. The two interfaces are placed in this VPN so they can connect to the WAN edge and establish secure tunnels (DTLS/TLS) with the vSmart controller; they are not used for end-user or customer traffic. This placement also allows vBond to orchestrate the overlay, and the interfaces are often physical ports or subinterfaces that provide underlay transport.
- ✗
The interfaces are in VPN 0, which is the service VPN, and they will be used for customer traffic.
Why it's wrong here
This statement incorrectly labels VPN 0 as a service VPN. In SD-WAN, service VPNs are numbered 1 through 512 and are specifically used to carry customer data between sites, while VPN 0 is exclusively reserved for the transport/underlay network. Interfaces in VPN 0 carry overlay control traffic and external transport, not customer traffic, so saying they are for customer traffic is wrong.
- ✗
The configuration is invalid because tunnel interfaces cannot have IP addresses in the same VPN.
Why it's wrong here
The configuration is not invalid because multiple tunnel interfaces can coexist within the same VPN 0 in SD-WAN, each with its own IP address representing a different underlay link. SD-WAN routers support many tunnel interfaces in the transport VPN to enable flexibility in WAN edge design, such as when using multiple transport providers. A single VPN is allowed to contain multiple tunnel interfaces, and they all use the transport VPN for overlay endpoint addressing.
- ✗
The 'allow-service all' command is not supported on vEdge routers.
Why it's wrong here
The 'allow-service all' command is absolutely supported on vEdge routers and is a common configuration used to permit all control and management services (like ICMP, SSH, and BFD) over a tunnel interface. This command is part of the vEdge CLI and is configured on tunnel interfaces in VPN 0 to control which services can traverse the overlay tunnel. Not being supported would contradict standard vEdge configuration examples and the SD-WAN architecture documentation.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.