A network engineer is troubleshooting a Cisco SD-WAN deployment. The engineer notices that a branch site's vEdge router is not establishing control connections to the vSmart controller. The vEdge has the correct system IP and organization name. Which action should the engineer take first to verify connectivity?
The vEdge must first connect to the vBond orchestrator to learn about vSmart and vManage. The vBond IP address must be correctly configured, and UDP port 12346 must be open for the DTLS control connection. If the vEdge cannot reach vBond, it will not obtain the vSmart information and cannot establish control connections. This is the first step in troubleshooting.
Why this answer
In Cisco SD-WAN, a vEdge router must first establish a control connection to the vBond orchestrator. This requires the vBond IP address to be configured and UDP port 12346 to be open. Once the vEdge authenticates with vBond, it receives the list of vSmart controllers and can then establish control connections to them.
Therefore, the first troubleshooting step is to verify vBond reachability.
Exam trap
The trap here is focusing on vSmart or vManage configuration before verifying the initial vBond connection, which is the prerequisite for all other control connections.