nerdexam
Cisco

300-440 · Question #9

Refer to the exhibit. An engineer needs to configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS). Which configuration command must be…

The correct answer is B. address 192.10.10.10. In the IKEv2 keyring configuration, the address command specifies the peer's public IP address. Since the AWS VPN peer in this setup is 192.10.10.10 (the tunnel destination), the correct command is address 192.10.10.10. This ensures the local router recognizes and authenticates…

IPsec Cloud Connectivity

Question

Refer to the exhibit. An engineer needs to configure a site-to-site IPsec VPN connection between an on-premises Cisco IOS XE router and Amazon Web Services (AWS). Which configuration command must be placed in the blank in the code to complete the tunnel configuration?

Exhibit

300-440 question #9 exhibit

Options

  • Aaddress 20.20.20.21
  • Baddress 192.10.10.10
  • Ctunnel source 20.20.20.21
  • Dtunnel source 192.10.10.10

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    79% (31)
  • C
    3% (1)
  • D
    5% (2)

Explanation

In the IKEv2 keyring configuration, the address command specifies the peer's public IP address. Since the AWS VPN peer in this setup is 192.10.10.10 (the tunnel destination), the correct command is address 192.10.10.10. This ensures the local router recognizes and authenticates AWS as its IKEv2 peer..

Topics

#IOS XE#AWS site-to-site VPN#tunnel configuration#IPsec

Community Discussion

No community discussion yet for this question.

Full 300-440 Practice