nerdexam
Cisco

300-415 · Question #220

What are the two reasons a customer chooses to use IPsec tunnels over GRE? (Choose two.)

The correct answer is D. A WAN Edge router is behind NAT. E. IPsec is more secure. Customers often choose IPsec tunnels over GRE due to enhanced security features and better compatibility with Network Address Translation (NAT) environments. IPsec inherently provides encryption and authentication, while its NAT traversal capabilities simplify deployment behind…

Security and Quality of Service

Question

What are the two reasons a customer chooses to use IPsec tunnels over GRE? (Choose two.)

Exhibit

300-415 question #220 exhibit

Options

  • AIPsec failure detection is faster.
  • BGenerally, they provide a higher bandwidth for tunnel connection.
  • CvFlowd is required.
  • DA WAN Edge router is behind NAT.
  • EIPsec is more secure.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    6% (2)
  • D
    89% (31)

Why each option

Customers often choose IPsec tunnels over GRE due to enhanced security features and better compatibility with Network Address Translation (NAT) environments. IPsec inherently provides encryption and authentication, while its NAT traversal capabilities simplify deployment behind firewalls.

AIPsec failure detection is faster.

While IPsec can utilize keepalives, its failure detection isn't inherently faster than GRE, which can also be combined with protocols like BFD for rapid failure detection.

BGenerally, they provide a higher bandwidth for tunnel connection.

GRE tunnels generally have lower overhead than IPsec due to fewer security operations, potentially offering slightly higher bandwidth efficiency in some scenarios, rather than IPsec providing higher bandwidth.

CvFlowd is required.

vFlowd is a Cisco proprietary flow monitoring daemon, not a general requirement or distinguishing factor between IPsec and GRE tunnel choices.

DA WAN Edge router is behind NAT.Correct

IPsec natively supports NAT traversal (NAT-T), allowing IPsec tunnels to be established even when one or both endpoints are behind a NAT device, which is a common scenario in enterprise networks.

EIPsec is more secure.Correct

IPsec provides robust security features, including data confidentiality (encryption), data integrity, and authentication, making it a more secure choice for protecting data in transit compared to GRE, which primarily encapsulates packets without inherent security.

Concept tested: IPsec vs. GRE Tunnel Features

Source: https://www.cisco.com/c/en/us/td/docs/routers/sdwan/configuration/sdwan-xe-gs-book/sdwan-security.html#concept_z5r_td2_vnb

Topics

#IPsec#GRE#Security#NAT Traversal

Community Discussion

No community discussion yet for this question.

Full 300-415 Practice