Why must the vBond orchestrator have a public IP in Cisco SD-WAN?
Choose an answer
Tap an option to check your answer.
Correct answer: to allow global reachability from all WAN Edges and enable NAT traversal.
Why this is the answer
The vBond orchestrator acts as the initial point of contact for all SD-WAN components (vEdges, vSmarts, vManage) joining the overlay network. For WAN Edges, especially those behind NAT or with private IP addresses, to discover and connect to the vBond, the vBond itself must be publicly reachable. This public IP allows for global reachability and facilitates NAT traversal, enabling the secure establishment of OMP (Overlay Management Protocol) and IPsec tunnels. Without a public IP, WAN Edges would be unable to locate and authenticate with the vBond, preventing them from joining the SD-WAN fabric. The other options are incorrect because: Cisco Smart Licensing is handled by vManage, not vBond. While vBond plays a role in discovery, it doesn't "learn" public IPs of WAN Edges in the way vManage or vSmart might track them; its primary role is initial authentication and orchestration. Software updates and patches are distributed by vManage, not vBond.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed