Courseiva
hardMultiple Choice

CCNP Practice Question: Is configuring a Cisco SD-WAN fabric with…

A network engineer is configuring a Cisco SD-WAN fabric with vManage, vSmart, and vBond controllers. The engineer wants to ensure that all branch routers automatically discover the vSmart and vManage controllers without manually configuring the vSmart or vManage addresses on each branch. The engineer has configured the vBond with a public IP address and enabled NAT traversal. However, branch routers are failing to establish control connections. The engineer verifies that the branch routers have the correct organization name but have not been configured with the vBond IP address. What is the most likely missing configuration?

⚠ Common exam trap

Cisco often tests the misconception that branch routers need the vSmart or vManage IP configured directly, when in fact the vBond is the single mandatory bootstrap address for automatic discovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vBond IP address is not configured on the branch routers.

In Cisco SD-WAN, branch routers use a two-phase discovery process: they first connect to the vBond controller to authenticate and receive the list of vSmart and vManage controllers. Since the engineer has already configured the vBond with a public IP and enabled NAT traversal, and the branch routers have the correct organization name, the missing piece is that the vBond IP address must be explicitly configured on each branch router (via the 'system vbond' CLI command or the equivalent in the device template). Without this, the branch routers have no initial target to contact for the bootstrap discovery process, so they cannot automatically learn the vSmart and vManage addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vManage IP address is not configured on the branch routers.

    Why it's wrong here

    The vManage IP address is not required during the initial ZTP/discovery phase; a vEdge router first contacts the vBond orchestrator, which authenticates the device and then supplies the vManage and vSmart addresses. The vManage is only the management plane, so omitting its IP in the bootstrap configuration would not prevent the control connections from being established. Therefore, this is not the cause of the branch routers failing to connect.

  • ✗

    The vSmart IP address is not configured on the branch routers.

    Why it's wrong here

    In Cisco SD-WAN, the vSmart controller address is learned dynamically after the vBond handshake, not statically configured on branch routers. Without a valid vBond endpoint, the router cannot request the vSmart list, so the absence of a vSmart IP is a symptom of the discovery failure rather than the root cause. The branch device only needs the vBond IP or FQDN to start the secure authentication and receive the controller list.

  • ✓

    The vBond IP address is not configured on the branch routers.

    Why this is correct

    The vBond orchestrator is the mandatory initial entry point in the SD-WAN discovery process: each branch router must have a configured vBond IP or resolvable vBond hostname to initiate the DTLS control-plane session. vBond authenticates the vEdge, verifies its identity, and then returns the IP addresses of vManage and vSmart for further configuration. Without this bootstrap value, the router cannot begin the fabric handshake, which precisely explains the symptoms in the scenario.

  • ✗

    The DTLS port 12346 is not open on the branch routers' firewall.

    Why it's wrong here

    While DTLS (the default control-plane protocol) uses UDP 12346 on the vBond, the engineer has already verified transport-layer reachability across the WAN, so a firewall drop is not indicated. Even if the port is open, the branch router has no destination address to target because the vBond IP is missing; the connection attempt cannot start. Thus, port 12346 blocking is not the correct explanation for the failure.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.