300-730 · Question #134
Which two components are required in a Cisco IOS GETVPN key server configuration? (Choose two.)
The correct answer is A. RSA key. A Cisco IOS GETVPN key server requires an RSA key pair to sign and distribute group policy via the GDOI protocol to registered group members.
Question
Options
- ARSA key
- BIKE policy
- CSSL cipher
- DGRE tunnel
- EL2TP protocol
How the community answered
(58 responses)- A91% (53)
- C2% (1)
- D5% (3)
- E2% (1)
Why each option
A Cisco IOS GETVPN key server requires an RSA key pair to sign and distribute group policy via the GDOI protocol to registered group members.
An RSA key pair is required on the GETVPN key server to cryptographically sign the GDOI rekey messages that deliver traffic encryption keys and group policy to all registered group members. Without the RSA key, the key server cannot authenticate itself during the GDOI registration exchange or securely push updated keying material to the group.
Although IKE is involved in the GETVPN registration phase, a discrete IKE policy entry is not the primary key-server-specific component being tested here - the RSA key is what uniquely defines the key server's signing and authentication capability.
SSL ciphers belong to TLS-based VPN solutions such as Cisco AnyConnect SSL VPN and have no role in GETVPN, which relies on IPsec and the GDOI key management protocol.
GRE tunnels are a component of DMVPN architectures; GETVPN is a tunnel-less solution that preserves the original IP header and does not encapsulate traffic in GRE.
L2TP is a Layer 2 tunneling protocol used in remote access dial-up or broadband VPN scenarios and plays no part in GETVPN's group-based IPsec key management architecture.
Concept tested: GETVPN key server RSA key requirement
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-get-vpn-xe-16-book/sec-get-vpn.html
Topics
Community Discussion
No community discussion yet for this question.