A 911 PSAP places SD-WAN controllers so Internet-transported Edges can reach them securely. What reachability design principle should lead?
Select an answer to reveal the explanation.
Short Explanation
If the firehouse Edge only has Internet transport, it still has to find the controllers. That means vBond and friends need reachable addresses—public or properly NATed—from VPN 0’s point of view. Hide them completely and onboarding never starts.
Full Explanation
SD-WAN Edges form control connections across the transport VPN toward the controller complex. When Edges use Internet transports, controller placement must provide reachable public addressing or equivalent NAT/port-forward design so DTLS/TLS control sessions can establish. Binding controllers only to service VPNs, relying on underlay multicast discovery, or making vBond unreachable from Internet transports breaks common onboarding paths.