nerdexam
Cisco

300-320 · Question #270

Which VPN technology supports dynamic creation of spoke-to-spoke VPN tunnels to provide a scalable design?

The correct answer is C. DMVPN. DMVPN (Dynamic Multipoint VPN) enables scalable hub-and-spoke VPN designs by allowing spokes to dynamically build direct spoke-to-spoke tunnels on demand using NHRP.

Advanced WAN Services

Question

Which VPN technology supports dynamic creation of spoke-to-spoke VPN tunnels to provide a scalable design?

Options

  • AIPsec
  • BGRE over IPsec
  • CDMVPN
  • DGRE

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    91% (40)
  • D
    2% (1)

Why each option

DMVPN (Dynamic Multipoint VPN) enables scalable hub-and-spoke VPN designs by allowing spokes to dynamically build direct spoke-to-spoke tunnels on demand using NHRP.

AIPsec

Standard IPsec requires statically defined crypto map peer configurations for each tunnel endpoint, providing no mechanism for dynamic spoke-to-spoke tunnel creation.

BGRE over IPsec

GRE over IPsec creates static point-to-point tunnels between explicitly configured endpoints and does not support dynamic spoke-to-spoke tunnel establishment.

CDMVPNCorrect

DMVPN uses a combination of mGRE (multipoint GRE), NHRP (Next Hop Resolution Protocol), and IPsec to allow spoke routers to register their public IP addresses with a hub and then dynamically build direct encrypted tunnels to other spokes without pre-configuring each tunnel, making it highly scalable.

DGRE

Plain GRE provides tunneling without encryption and requires static point-to-point configurations with no dynamic spoke-to-spoke capability.

Concept tested: DMVPN dynamic spoke-to-spoke tunnel creation using NHRP

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/xe-16/sec-conn-dmvpn-xe-16-book.html

Topics

#DMVPN#spoke-to-spoke tunnels#VPN scalability

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice