WAN Edge Registration with Enterprise CA Certificates

Answer Correct answer: B, D — Generate a CSR manually within vManage server and Install the certificate received from the CA server manually on the vManage.

Refer to the exhibit. Which two configurations are needed to get the WAN Edges registered with the controllers when certificates are used? (Choose two.) - image

  1. Install the certificate received from the CA server manually on the WAN Edge.
  2. Generate a CSR manually within vManage server. Correct Answer
  3. Generate a CSR manually on the WAN Edge.
  4. Install the certificate received from the CA server manually on the vManage. Correct Answer
  5. Request a certificate manually from the Enterprise CA server.

Community Votes

BD
53%
AE
47%

53% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the distinction between manual CSR generation on the edge versus controller-managed CSR generation when using an Enterprise CA in a multi-controller environment.

This page explains the correct certificate workflow for registering Cisco SD-WAN WAN Edges to vManage controllers using an Enterprise CA. It clarifies that CSR generation must occur on the controller (vManage) and certificates must be installed there, distinguishing this from manual edge-based enrollment.

Many learners choose A and E because they assume the edge device must generate its own CSR and request the certificate manually, which is incorrect for the standard Enterprise CA integration pattern shown in the exhibit.

Community Discussion (7 comments)

rubendrios 👍 2 Selected: AE
1 and 2 clearly states what to do to configure https://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/SDWAN/sdwan-wan-edge-onboarding-deploy-guide-2020nov.pdf
Networkchamp87 👍 1 Selected: AE
To On-board a WAN edge using enterprise CA [which is the exact same lab setup by Keith B on CBTnug) You need to put a root cert on the edge, which you pull from the vmanage using the request file command. You then need to install it by using the request " request root-cert-chain install" https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/221605-install-root-certificate-on-sdwan-vedges.html
PureInertiaCopy 👍 2 Selected: AE
BD don't make sense to me . I think it's A and E
Networkchamp87 👍 3 Selected: BD
Enterprise - Mean you are using an Enterprise CA, not Default / Cloud I.E Cisco & DigiCert. Process for that is B,D.
RafaJohnston76 👍 2 Selected: BD
I believe is BD https://www.cisco.com/c/en/us/td/docs/solutions/CVD/SDWAN/cisco-sdwan-controller-cert-deploy-guide.html
Outlaw_87 👍 2 Selected: AE
In the picture it shows Enterprise not Manual. So, B and C eliminates. If Controller Certificate Authorization shows Enterprise I hope certificate from CA is already installed in vManage. So, D eliminates. Remains A and E.
Knowledge33 👍 3 Selected: BD
B and D are correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

When integrating Cisco SD-WAN WAN Edges with an Enterprise CA in a multi-vManage environment, the recommended and supported workflow involves the vManage controllers handling the Certificate Signing Request (CSR) generation. Option B is correct because you must generate the CSR within the vManage server (or via the vManage API/UI) so it can sign the certificate against the Enterprise CA. Option D is correct because the resulting signed certificate must be installed on the vManage controller to facilitate the trust chain for the WAN Edges. This allows the WAN Edges to register securely without needing direct access to the CA or manual certificate management on every edge device.

Why the Other Options Are Wrong

Options A, C, and E describe a manual enrollment process where the edge generates a CSR (C), requests the cert (E), and installs it (A). While technically possible in isolated setups, this is not the standard 'Enterprise CA' configuration implied by the exhibit and exam doctrine for registered WAN Edges. The term 'registered' implies the controller manages the identity. Option C is wrong because generating CSRs manually on the WAN Edge bypasses the controller's ability to manage the certificate lifecycle. Option E is wrong because the edge does not directly request certificates from the Enterprise CA in this architecture; the vManage acts as the intermediary.

Community Comment Notes

Community discussion is split between BD and AE. Users like Networkchamp87 and Knowledge33 correctly identify BD based on official Cisco deployment guides. However, several users (e.g., PureInertiaCopy, Outlaw_87) argue for AE, citing lab experiences or specific manual configurations. One user noted that if the picture shows 'Enterprise', it implies the CA is already trusted, but the exam question specifically asks for the configuration needed to get them registered, which points to the controller-side actions. As one commenter stated, 'Process for that is B,D,' aligning with the official SD-WAN Controller Certificate Deploy Guide.

Official Reference

Exam Strategy

For SD-WAN security questions involving 'Enterprise CA' and 'Registration', always look for options where the vManage controller handles the CSR and certificate installation. Avoid options that suggest manual interaction on the WAN Edge unless the question explicitly states 'Manual Enrollment'.

Frequently Asked Questions

Why can't the WAN Edge generate its own CSR?

In the Enterprise CA model, the vManage controller manages the certificate lifecycle. The edge trusts the vManage, so the vManage generates the CSR and installs the final cert to authenticate the edge.

What is the difference between Manual and Enterprise CA?

Manual CA requires the edge to handle all CSR and installation steps. Enterprise CA integrates with a corporate PKI where vManage facilitates the signing process, simplifying edge management.

Related Analysis

Practice All 300-415 Questions

Access 120 questions with complete answers and detailed explanations.

View Full 300-415 Practice Test →

← Back to 300-415 Study Guide