nerdexam
Cisco

200-301 · Question #1794

Which IPsec mode provides encapsulation and encryption of the entire original IP packet on a site-to-site VPN?

The correct answer is B. tunnel. IPsec tunnel mode encrypts and encapsulates the entire original IP packet (header and payload) inside a new IP packet, which is required for site-to-site VPNs.

Submitted by lucia.co· Mar 5, 2026

Question

Which IPsec mode provides encapsulation and encryption of the entire original IP packet on a site-to-site VPN?

Options

  • Aaggressive
  • Btunnel
  • Cmain
  • Dtransport

How the community answered

(26 responses)
  • B
    88% (23)
  • C
    8% (2)
  • D
    4% (1)

Explanation

IPsec tunnel mode encrypts and encapsulates the entire original IP packet (header and payload) inside a new IP packet, which is required for site-to-site VPNs.

Topics

#IPsec modes#VPN encapsulation#site-to-site VPN

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice