300-730 · Question #147
Refer to the exhibit. Which component must be configured on routers for a GETVPN deployment work properly?
The correct answer is A. PE3: Key Server - Customer 2 CEs: Group Members. In GETVPN, the Key Server distributes encryption policy and keys to Group Members, and in a service provider MPLS topology the PE router acts as Key Server while the customer CEs of the relevant segment act as Group Members.
Question
Options
- APE3: Key Server - Customer 2 CEs: Group Members
- BCustomer 1 CE1: Key Server - R1 and Customer 1 CE2: Group Members
- CR1: Key Server - Customer 1 CEs: Group Members
- DPE3: Key Server - all CEs: Group Members
How the community answered
(33 responses)- A79% (26)
- B3% (1)
- C12% (4)
- D6% (2)
Why each option
In GETVPN, the Key Server distributes encryption policy and keys to Group Members, and in a service provider MPLS topology the PE router acts as Key Server while the customer CEs of the relevant segment act as Group Members.
GETVPN requires a Key Server to register Group Members, distribute TEK/KEK keys, and push GDOI policy. PE3 serving as Key Server for Customer 2 CEs as Group Members is architecturally correct because GETVPN operates within a single routing domain and each customer segment maintains its own isolated KS/GM relationship.
Placing Customer 1 CE1 as the Key Server positions the KS at the customer edge rather than in the service provider core, which is not the standard GETVPN provider deployment model.
R1 as Key Server for Customer 1 CEs contradicts the exhibit topology where PE3 is the designated core device positioned to manage the relevant customer group's GDOI registrations.
A single PE acting as Key Server for all CEs across all customer segments would merge GETVPN groups across different customer VPNs, violating traffic separation and the one-group-per-policy-domain requirement.
Concept tested: GETVPN Key Server and Group Member roles in MPLS topology
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-get-vpn-xe-16-book/sec-get-vpn.html
Topics
Community Discussion
No community discussion yet for this question.