Which VPNs Must Be Configured Outside the SD-WAN Quick Connect Workflow?

Answer Correct answer: A — Service VPNs must be configured outside the Quick Connect workflow, which only provisions WAN transport settings in VPN 0.

Which VPNs must be configured outside the workflow to complete the SD-WAN overlay setup when using the Quick Connect workflow?

  1. service VPNs Correct Answer
  2. transport VPNs
  3. service and transport VPNs
  4. management VPNs

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests knowledge of the Quick Connect workflow's built-in restriction, with the trap of assuming the workflow also handles service or management VPNs.

In Cisco Catalyst SD-WAN, the Quick Connect workflow only provisions WAN transport settings in VPN 0, so service VPNs must be configured separately to complete the overlay. This page confirms why option A is the correct answer.

Selecting C (service and transport VPNs) because candidates assume Quick Connect configures all VPN types, but transport VPN 0 is exactly what the workflow handles.

Community Discussion (3 comments)

Rosh8787 👍 1
Option A. Check the restriction for quick connect workflow section in below link. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/m-quick-connect-workflow.html
Zamochit 👍 1 Selected: A
Restrictions for Quick Connect Workflow The Quick Connect workflow is limited to configuring WAN settings (VPN 0). To be able to complete the Cisco Catalyst SD-WAN overlay bring up process, you also need to configure service-side VPN templates. For detailed information about configuring network interfaces, see Configure Network Interfaces. The Quick Connect workflow is supported for Cisco Catalyst SD-WAN Device (IOS XE) devices only. The Quick Connect workflow supports creating day-0 configurations for a maximum of 25 devices at a time. If you have more than 25 devices, run the workflow more than once, as applicable. You can have only one in-progress workflow at any given point.
Outlaw_87 👍 2 Selected: A
Restrictions for Quick Connect Workflow The Quick Connect workflow is limited to configuring WAN settings (VPN 0). To be able to complete the Cisco Catalyst SD-WAN overlay bring up process, you also need to configure service-side VPN templates. https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/m-quick-connect-workflow.html

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The Cisco Catalyst SD-WAN Quick Connect workflow is deliberately scoped to WAN transport configuration — it configures the transport VPN (VPN 0) and its interfaces, but it does not create service-side VPNs. To bring up the overlay and pass actual service traffic, you must configure service VPN templates outside the workflow. Thus, the VPNs that "must be configured outside the workflow" are service VPNs, making A correct. This matches Cisco's documented restriction and the community's unanimous read.

Why the Other Options Are Wrong

B is wrong because transport VPNs (VPN 0) are precisely what Quick Connect configures, so they are not the outside-workflow requirement. C is wrong for the same reason: it wrongly bundles transport VPNs, which the workflow already handles, with the service VPNs that it does not. D is wrong because management VPNs are not the missing piece for completing the overlay under Quick Connect; management connectivity is typically separate and optional in this context. None of these alternatives reflect the documented Quick Connect limitation.

Community Comment Notes

Outlaw_87 points directly to Cisco's restriction, quoting "The Quick Connect workflow is limited to configuring WAN settings (VPN 0)." and adds that "you also need to configure service-side VPN templates." Rosh8787 also selects option A and directs readers to the same Cisco restrictions section. Zamochit repeats the identical restriction language and confirms service-side VPN templates are required. The comment record is consistent, but the answer stands on Cisco's documented behavior, not on the vote count.

Official Reference

Exam Strategy

Memorize the exact scope of each SD-WAN onboarding workflow: Quick Connect equals WAN/transport VPN 0 only, while service VPNs are always a separate step. On the exam, eliminate answers that include transport VPNs as "outside" configuration because those are already covered.

Frequently Asked Questions

Why are service VPNs needed outside the Quick Connect workflow?

Quick Connect only configures WAN transport settings in VPN 0, so service-side VPN templates must be added separately to complete the SD-WAN overlay and carry service traffic.

Does the Quick Connect workflow configure management VPNs?

No, Quick Connect focuses on WAN transport VPN 0; management and service VPNs are outside its scope, and only service VPNs are required to finish the overlay bring-up.

Related Analysis

Practice All 300-415 Questions

Access 120 questions with complete answers and detailed explanations.

View Full 300-415 Practice Test →

← Back to 300-415 Study Guide