nerdexam
Cisco

300-320 · Question #126

Which of these is true of IP addressing with regard to VPN termination?

The correct answer is A. addressing designs need to allow for summarization. Best design practices say the VPN design should allow for summarization. With regards to D - sometimes you cannot avoid overlapping addresses as this is what is configured at client's end, and the only option is to hide the overlapping subnet behind NAT - based on experience…

Advanced Addressing and Routing Solutions

Question

Which of these is true of IP addressing with regard to VPN termination?

Options

  • Aaddressing designs need to allow for summarization
  • Btermination devices need routable addresses inside the VPN
  • CIGP routing protocols will update their routing tables over an IPsec VPN
  • Ddesigns should not include overlapping address spaces between sites, since NAT is not

How the community answered

(53 responses)
  • A
    92% (49)
  • B
    2% (1)
  • C
    2% (1)
  • D
    4% (2)

Explanation

Best design practices say the VPN design should allow for summarization. With regards to D - sometimes you cannot avoid overlapping addresses as this is what is configured at client's end, and the only option is to hide the overlapping subnet behind NAT - based on experience (The author of this remark has 50x VPN tunnels and majority of them is using NAT, even if the subnet doesn't overlap, we want to hide our real IPs behind something else - extra security)

Topics

#VPN#IP addressing#route summarization#IPsec design

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice