nerdexam
Cisco

300-730 · Question #147

Refer to the exhibit. Which component must be configured on routers for a GETVPN deployment work properly?

The correct answer is A. PE3: Key Server - Customer 2 CEs: Group Members. In GETVPN, the Key Server distributes encryption policy and keys to Group Members, and in a service provider MPLS topology the PE router acts as Key Server while the customer CEs of the relevant segment act as Group Members.

Site-to-site VPNs on Routers and Firewalls

Question

Refer to the exhibit. Which component must be configured on routers for a GETVPN deployment work properly?

Options

  • APE3: Key Server - Customer 2 CEs: Group Members
  • BCustomer 1 CE1: Key Server - R1 and Customer 1 CE2: Group Members
  • CR1: Key Server - Customer 1 CEs: Group Members
  • DPE3: Key Server - all CEs: Group Members

How the community answered

(33 responses)
  • A
    79% (26)
  • B
    3% (1)
  • C
    12% (4)
  • D
    6% (2)

Why each option

In GETVPN, the Key Server distributes encryption policy and keys to Group Members, and in a service provider MPLS topology the PE router acts as Key Server while the customer CEs of the relevant segment act as Group Members.

APE3: Key Server - Customer 2 CEs: Group MembersCorrect

GETVPN requires a Key Server to register Group Members, distribute TEK/KEK keys, and push GDOI policy. PE3 serving as Key Server for Customer 2 CEs as Group Members is architecturally correct because GETVPN operates within a single routing domain and each customer segment maintains its own isolated KS/GM relationship.

BCustomer 1 CE1: Key Server - R1 and Customer 1 CE2: Group Members

Placing Customer 1 CE1 as the Key Server positions the KS at the customer edge rather than in the service provider core, which is not the standard GETVPN provider deployment model.

CR1: Key Server - Customer 1 CEs: Group Members

R1 as Key Server for Customer 1 CEs contradicts the exhibit topology where PE3 is the designated core device positioned to manage the relevant customer group's GDOI registrations.

DPE3: Key Server - all CEs: Group Members

A single PE acting as Key Server for all CEs across all customer segments would merge GETVPN groups across different customer VPNs, violating traffic separation and the one-group-per-policy-domain requirement.

Concept tested: GETVPN Key Server and Group Member roles in MPLS topology

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-get-vpn-xe-16-book/sec-get-vpn.html

Topics

#GETVPN#Key Server#Group Member#GDOI

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice