Authentication: As mentioned, the Cisco SD-WAN control plane contributes the underlying infrastructure for data plane security. In addition, authentication is enforced by two other mechanisms: In the traditional key exchange model, the Cisco vSmart Controller sends IPsec encryption keys to each edge device https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/security/vedge-20-x/security- book/security-overview.html