Courseiva
mediumMultiple Choice

CCNP Practice Question: Examine the following SD-WAN configuration on a…

Examine the following SD-WAN configuration on a Cisco vEdge router:

vpn 0

interface ge0/0
 ip address 10.0.0.1/24

tunnel-interface

encapsulation ipsec

color public-internet allow-service all !

interface ge0/1
 ip address 10.0.0.2/24

tunnel-interface

encapsulation ipsec

color 3g allow-service all !

Which statement is correct?

⚠ Common exam trap

Cisco often tests the misconception that VPN 0 is a service VPN or that multiple tunnel interfaces in the same VPN are invalid, but the key is remembering that VPN 0 is strictly the transport underlay and supports multiple colored interfaces for control-plane connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Both interfaces are in VPN 0, which is the transport VPN, and they will establish tunnels with the vSmart controller.

VPN 0 is the transport VPN in Cisco SD-WAN, used exclusively for underlay network connectivity and control plane traffic. The two interfaces ge0/0 and ge0/1 are configured as tunnel interfaces with IPsec encapsulation and different colors (public-internet and 3g), which allows them to establish secure DTLS/TLS tunnels to the vSmart controller for orchestration and policy distribution. This is correct because transport VPN interfaces are designed to carry overlay control traffic, not customer data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Both interfaces are in VPN 0, which is the transport VPN, and they will establish tunnels with the vSmart controller.

    Why this is correct

    In Cisco SD-WAN, VPN 0 is the dedicated transport VPN that carries underlay connectivity and control plane traffic. The two interfaces are placed in this VPN so they can connect to the WAN edge and establish secure tunnels (DTLS/TLS) with the vSmart controller; they are not used for end-user or customer traffic. This placement also allows vBond to orchestrate the overlay, and the interfaces are often physical ports or subinterfaces that provide underlay transport.

  • ✗

    The interfaces are in VPN 0, which is the service VPN, and they will be used for customer traffic.

    Why it's wrong here

    This statement incorrectly labels VPN 0 as a service VPN. In SD-WAN, service VPNs are numbered 1 through 512 and are specifically used to carry customer data between sites, while VPN 0 is exclusively reserved for the transport/underlay network. Interfaces in VPN 0 carry overlay control traffic and external transport, not customer traffic, so saying they are for customer traffic is wrong.

  • ✗

    The configuration is invalid because tunnel interfaces cannot have IP addresses in the same VPN.

    Why it's wrong here

    The configuration is not invalid because multiple tunnel interfaces can coexist within the same VPN 0 in SD-WAN, each with its own IP address representing a different underlay link. SD-WAN routers support many tunnel interfaces in the transport VPN to enable flexibility in WAN edge design, such as when using multiple transport providers. A single VPN is allowed to contain multiple tunnel interfaces, and they all use the transport VPN for overlay endpoint addressing.

  • ✗

    The 'allow-service all' command is not supported on vEdge routers.

    Why it's wrong here

    The 'allow-service all' command is absolutely supported on vEdge routers and is a common configuration used to permit all control and management services (like ICMP, SSH, and BFD) over a tunnel interface. This command is part of the vEdge CLI and is configured on tunnel interfaces in VPN 0 to control which services can traverse the overlay tunnel. Not being supported would contradict standard vEdge configuration examples and the SD-WAN architecture documentation.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.