Which vManage CLI configuration enables automated certificate signing through Cisco?
Choose an answer
Tap an option to check your answer.
Correct answer: vpn 0 dns 208.67.222.222 primary allow-service dns allow-service sshd allow-service netconf.
Why this is the answer
The correct command is vpn 0 dns 208.67.222.222 primary allow-service dns allow-service sshd allow-service netconf. For automated certificate signing with Cisco, the vManage instance must be able to resolve DNS names. This requires configuring a DNS server within VPN 0, which is the transport VPN. The dns 208.67.222.222 primary part specifies a primary DNS server (OpenDNS in this case) for VPN 0. The allow-service dns allow-service sshd allow-service netconf part enables necessary services for device management and communication. Options using vpn 512 are incorrect because VPN 512 is the management VPN for local device access, not the transport VPN used for certificate signing and general control plane communication. Options missing the dns configuration are also incorrect as DNS resolution is crucial for automated certificate signing.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed