300-730 · Question #21
Which statement about GETVPN is true?
The correct answer is A. The configuration that defines which traffic to encrypt originates from the key server. In GETVPN, the key server centrally defines and distributes the traffic encryption policy as part of the Group Security Association to all registered group members.
Question
Options
- AThe configuration that defines which traffic to encrypt originates from the key server.
- BTEK rekeys can be load-balanced between two key servers operating in COOP.
- CThe pseudotime that is used for replay checking is synchronized via NTP.
- DGroup members must acknowledge all KEK and TEK rekeys, regardless of configuration.
How the community answered
(29 responses)- A90% (26)
- B3% (1)
- D7% (2)
Why each option
In GETVPN, the key server centrally defines and distributes the traffic encryption policy as part of the Group Security Association to all registered group members.
The GETVPN key server is the authoritative source of policy - it defines the access control list specifying which traffic to encrypt and pushes this policy along with the Traffic Encryption Keys (TEKs) to all registered group members. Group members apply the policy received from the key server rather than configuring encryption policy locally.
In a COOP key server configuration, one key server is elected primary and performs all rekeys while the secondary is a hot standby that only takes over if the primary fails - TEK rekeys are not load-balanced between the two.
GETVPN anti-replay uses a pseudotime value distributed by the key server to group members as part of the Group SA, making it independent of NTP and not synchronized via NTP.
GETVPN supports both unicast and multicast rekey methods - multicast rekey does not require acknowledgment from group members, so whether acknowledgment is required depends on the configured rekey transport method.
Concept tested: GETVPN key server centralized traffic encryption policy distribution
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-conn-getvpn-xe-16-book/sec-conn-getvpn-getvpn.html
Topics
Community Discussion
No community discussion yet for this question.