nerdexam
Cisco

300-730 · Question #205

Refer to the exhibit. Which remote access technology is used in the configuration?

The correct answer is A. DMVPN. DMVPN is identified in a configuration by a multipoint GRE (mGRE) tunnel interface combined with NHRP commands for dynamic spoke-to-spoke resolution.

Site-to-site VPNs on Routers and Firewalls

Question

Refer to the exhibit. Which remote access technology is used in the configuration?

Options

  • ADMVPN
  • BClientless SSL VPN
  • CGET VPN
  • DGRE VPN

How the community answered

(29 responses)
  • A
    90% (26)
  • B
    7% (2)
  • D
    3% (1)

Why each option

DMVPN is identified in a configuration by a multipoint GRE (mGRE) tunnel interface combined with NHRP commands for dynamic spoke-to-spoke resolution.

ADMVPNCorrect

DMVPN configurations are uniquely characterized by 'tunnel mode gre multipoint' on the tunnel interface and 'ip nhrp' commands (network-id, map, nhs) for dynamic NBMA-to-tunnel address mapping - these CLI elements are the definitive signatures that distinguish DMVPN from all other VPN types.

BClientless SSL VPN

Clientless SSL VPN is configured using WebVPN context blocks and HTTPS-based portal settings - it has no GRE tunnel interfaces or NHRP configuration.

CGET VPN

GET VPN is configured using a GDOI key server and group member ('crypto gdoi group') configuration - it encrypts traffic in-place without any tunnel interface.

DGRE VPN

A standard point-to-point GRE VPN uses a single static 'tunnel destination' and does not include 'tunnel mode gre multipoint' or any NHRP configuration.

Concept tested: Identifying DMVPN configuration by CLI signatures

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/xe-16/sec-conn-dmvpn-xe-16-book/sec-conn-dmvpn.html

Topics

#DMVPN#VPN identification#mGRE#tunnel configuration

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice