Cisco
300-730 · Question #149
300-730 Question #149: Real Exam Question with Answer & Explanation
Sign in or unlock 300-730 to reveal the answer and full explanation for question #149. The question stem and answer options stay visible for context.
Troubleshooting VPNs
Question
A network administrator is troubleshooting a FlexVPN tunnel. The hub router is unable to ping the spoke router's tunnel interface IP address of 192.168.1.2, even though the tunnel is showing up. The output of the debug ip packet CLI command on the hub router shows the following entry: IP: tableid=0123456789 s=192.168.1.1 (local), d=192.168.1.2 (loopback2), routed via FIB. What must be configured to fix this issue?
Options
- AA matching IKEv2 pre-shared key on the hub and spoke routers in the crypto keying configuration.
- BAn outbound ACL on the dynamic VTI of the hub router that allows ICMP traffic to 192.168.1.2.
- CAn IKEv2 authorization policy must be configured on the spoke router to advertise the interface route.
- DA route map must be configured on hub router to set the next hop for 192.168.1.2 to the dynamic VTI.
Unlock 300-730 to see the answer
You've previewed enough free 300-730 questions. Unlock 300-730 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#FlexVPN#IKEv2 authorization policy#DVTI#routing