300-730 · Question #224
An engineer must design a VPN solution that meet these requirements: internet connections to the cloud creates a private tunnel for direct communication between corporate sites encrypts the tunnels…
The correct answer is D. DMVPN. DMVPN is the only listed technology that simultaneously uses internet connections as transport, creates private multipoint GRE tunnels between corporate sites, and encrypts those tunnels with IPsec.
Question
- internet connections to the cloud
- creates a private tunnel for direct communication between corporate sites
- encrypts the tunnels by using IPsec Which technology must be used?
Exhibit
Options
- ASSL VPN
- BGET VPN
- CWebVPN
- DDMVPN
How the community answered
(59 responses)- A2% (1)
- B5% (3)
- C2% (1)
- D92% (54)
Why each option
DMVPN is the only listed technology that simultaneously uses internet connections as transport, creates private multipoint GRE tunnels between corporate sites, and encrypts those tunnels with IPsec.
SSL VPN uses TLS rather than IPsec for encryption and is designed for remote-access client connectivity, not private site-to-site tunneling.
GET VPN requires a private MPLS network as its transport and relies on a Key Server; it does not operate over internet connections.
WebVPN is a clientless browser-based remote-access solution secured with SSL/TLS and is not designed for site-to-site private encrypted tunnels between corporate locations.
DMVPN uses a public internet connection as its underlay transport and builds private site-to-site tunnels using multipoint GRE (mGRE) combined with NHRP for dynamic spoke discovery. IPsec is applied as an IPsec profile directly on the tunnel interface, satisfying the encryption requirement - making DMVPN the single technology that fulfills all three stated requirements simultaneously.
Concept tested: DMVPN as internet-based site-to-site IPsec VPN solution
Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/WAN_and_MAN/DMVPN_2_Phase3/DMVPN_Phase_3_Aug11.html
Topics
Community Discussion
No community discussion yet for this question.
