This document describes how to configure the host entry for Software Defined Wide Area Network (SD-WAN) Authenticator.
Cisco recommends that you have knowledge of these topics:
The information in this document is based on these software and hardware versions:
The information in this document was created from the devices in a specific lab environment. All of the devices used in this document started with a cleared (default) configuration. If your network is live, ensure that you understand the potential impact of any command.
Configure the vBond host entry when there are Domain Name Server (DNS) issues such as, but not limited to:
This document assumes:
This is an example of a common configuration with FQDN:
vedge# show running-config system vbond system vbond vbond.lab.sdwan ! vedge# show running-config vpn 0 dns vpn 0 dns 192.168.1.11 primary !
This is the expected result when DNS translation works properly:
vedge# nslookup vbond.lab.sdwan nslookup in VPN 0: Server: 192.168.1.11 Address 1: 192.168.1.11 Name: vbond.lab.sdwan Address 1: 192.168.2.1 vbond.lab.sdwan Address 2: 192.168.2.2 vbond.lab.sdwan vedge# ping vbond.lab.sdwan Ping in VPN 0 PING vbond.lab (192.168.2.1) 56(84) bytes of data. 64 bytes from vbond.lab (192.168.2.1): icmp_seq=1 ttl=63 time=26.1 ms
This configuration is the same as the previous scenario:
vedge# show running-config system vbond system vbond vbond.lab.sdwan ! vedge# show running-config vpn 0 dns vpn 0 dns 192.168.1.11 primary !
This time, DNS resolution fails:
vedge#nslookup vbond.lab.sdwan
nslookup in VPN 0:
Server: 192.168.1.11
Address 1: 192.168.1.11
nslookup: can't resolve 'vbond.lab.sdwan'
vedge#
vedge# ping vpn 0 vbond.lab.sdwan
Ping in VPN 0
ping: vbond.lab.sdwan: Name or service not known
vedge#
Configure the host command with FQDN and vBond IPs:
vedge# show running-config vpn 0 host vpn 0 host vbond.lab.sdwan ip 192.168.2.1 192.168.2.2 ! vedge#
Run the nslookup command for validation purposes:
vedge# nslookup vbond.lab.sdwan
nslookup in VPN 0:
Server: 192.168.1.11
Address 1: 192.168.1.11
Name: vbond.lab.sdwan
Address 1: 192.168.2.1 vbond.lab.sdwan
Address 2: 192.168.2.2 vbond.lab.sdwan
The configuration is the same as vEdge devices. This is an example of the controller:
vsmart# show running-config system vbond system vbond vbond.lab.sdwan ! vsmart# show running-config vpn 0 dns vpn 0 dns 192.168.1.11 primary !
vsmart# show running-config vpn 0 host vpn 0 host vbond.lab.sdwan ip 192.168.2.1 192.168.2.2 ! vsmart#
This is the configuration for the Cisco Edge Router:
cedge#show sdwan run system | include vbond
vbond vbond-list
cedge#
cedge#show sdwan run | include host
ip host vbond-list 192.168.2.1 192.168.2.2
cedge#
Run ICMP for validation purposes:
cedge#ping vbond-list
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.50.149, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 27/29/31 ms
cedge#
Set the primary and secondary DNS server as a redundancy method. This is in case one server fails and the other forms a DNS resolution.
The next example applies to vEdge, Manager, and Controller:
VM# show running-config vpn 0 dns vpn 0 dns 192.168.1.11 secondary dns 192.168.1.12 primary !
The next example applies for cEdge:
cedge#show run | i name
ip name-server 192.168.30.32 192.168.48.89
cedge#
| Revision | Publish Date | Comments |
|---|---|---|
2.0 |
10-Sep-2026
|
Updated title, spelling, grammar, inserted horizontal lines to separate sections for readability, fixed CCW alerts. |
1.0 |
11-Apr-2023
|
Initial Release |