300-415 Question 309
Select 3An organization has deployed Cisco SD-WAN in its network and wants to configure authentication for vEdge devices to ensure secure communication. They also need to enable monitoring and reporting for better visibility into network operations. Which of the following steps are required to meet these requirements?
- A
Configure a root certificate on the vManage to authenticate vEdge devices.
- B
Enable SNMP on vManage to allow external monitoring tools to gather network statistics.
- C
Deploy NetFlow configurations to monitor application usage and generate flow-based reports.
- D
Ensure vEdge devices are enrolled using a valid device certificate issued by the Cisco SD-WAN CA.
- E
Configure syslog servers on the vSmart controllers for centralized logging and reporting.
Show answer and explanation
Correct answers: A, B, D
Explanation
To configure authentication, monitoring, and reporting in Cisco SD-WAN, it is necessary to set up a root certificate for vEdge authentication, enable SNMP for external monitoring, and ensure all vEdge devices are enrolled with valid device certificates. These steps collectively ensure secure communication, visibility into network performance, and compliance with organizational policies.
- A. Correct.
Correct: Configuring a root certificate on vManage is essential for authenticating vEdge devices in the Cisco SD-WAN environment. This ensures secure communication between devices and controllers.
- B. Correct.
Correct: Enabling SNMP on vManage allows external monitoring tools to gather network statistics, which is an essential part of monitoring in Cisco SD-WAN.
- C. Incorrect.
Incorrect: While NetFlow is used for monitoring traffic and application usage, it is not directly integrated with Cisco SD-WAN-specific monitoring and reporting features.
- D. Correct.
Correct: Enrolling vEdge devices with a valid device certificate issued by the Cisco SD-WAN CA ensures secure communication and authentication within the Cisco SD-WAN fabric.
- E. Incorrect.
Incorrect: Syslog servers are used for centralized logging but are not a mandatory part of the primary configuration for authentication, monitoring, and reporting in Cisco SD-WAN.