nerdexam
Cisco

300-320 · Question #337

IP multicast packets when designing IPSec VPN?

The correct answer is B. Encapsulation of trafic with GRE or VTI. IPSec natively cannot encrypt multicast or broadcast traffic - it is designed only for unicast IP traffic. To carry multicast traffic over an IPSec VPN, you must first encapsulate the multicast packets inside a unicast tunnel. GRE (Generic Routing Encapsulation) tunnels or VTI…

Advanced WAN Services

Question

IP multicast packets when designing IPSec VPN?

Options

  • AIPSec forwarding using tunnle mode
  • BEncapsulation of trafic with GRE or VTI
  • CAdditional bandwidth for headend
  • DIPSec forwarding using transport mode

How the community answered

(63 responses)
  • A
    3% (2)
  • B
    76% (48)
  • C
    6% (4)
  • D
    14% (9)

Explanation

IPSec natively cannot encrypt multicast or broadcast traffic - it is designed only for unicast IP traffic. To carry multicast traffic over an IPSec VPN, you must first encapsulate the multicast packets inside a unicast tunnel. GRE (Generic Routing Encapsulation) tunnels or VTI (Virtual Tunnel Interface) accomplish this: GRE/VTI wraps the multicast packet inside a unicast IP packet, and IPSec then encrypts that unicast outer packet normally. This is a fundamental limitation of IPSec that every network designer must account for. The GRE-over-IPSec or IPSec VTI design pattern is the standard solution for any network that needs to pass multicast (e.g., routing protocols like EIGRP/OSPF, or application multicast) across an IPSec VPN.

Topics

#IPSec VPN#multicast#GRE tunneling#VTI

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice