nerdexam
Cisco

300-440 · Question #4

An engineer must configure an IPsec tunnel to the cloud VPN gateway. Which Two actions send traffic into the tunnel? (Choose two.)

The correct answer is A. Configure access lists that match the interesting user traffic. B. Configure a static route. To send traffic into an IPsec tunnel, the router needs two main components: Identification of "interesting" traffic: An access list is used to define which specific traffic (based on source/destination IP addresses, ports, etc.) should be encrypted and sent over the VPN. This…

IPsec Cloud Connectivity

Question

An engineer must configure an IPsec tunnel to the cloud VPN gateway. Which Two actions send traffic into the tunnel? (Choose two.)

Options

  • AConfigure access lists that match the interesting user traffic.
  • BConfigure a static route.
  • CConfigure a local policy in Cisco vManage.
  • DConfigure an IPsec profile and match the remote peer IP address.
  • EConfigure policy-based routing.

How the community answered

(25 responses)
  • A
    72% (18)
  • C
    4% (1)
  • D
    8% (2)
  • E
    16% (4)

Explanation

To send traffic into an IPsec tunnel, the router needs two main components: Identification of "interesting" traffic: An access list is used to define which specific traffic (based on source/destination IP addresses, ports, etc.) should be encrypted and sent over the VPN. This is part of a policy-based VPN configuration. Forwarding the identified traffic: A static route (or dynamic routing) is required to direct traffic destined for the remote network into the tunnel interface.

Topics

#IPsec tunnel#ACL#static routing#cloud VPN gateway

Community Discussion

No community discussion yet for this question.

Full 300-440 Practice