nerdexam
Cisco

300-730 · Question #34

Which configuration construct must be used in a FlexVPN tunnel?

The correct answer is D. IKEv2 profile. FlexVPN is an IKEv2-based VPN framework, making the IKEv2 profile a mandatory configuration element to establish any FlexVPN tunnel.

Site-to-site VPNs on Routers and Firewalls

Question

Which configuration construct must be used in a FlexVPN tunnel?

Options

  • AEAP configuration
  • Bmultipoint GRE tunnel interface
  • CIKEv1 policy
  • DIKEv2 profile

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    6% (1)
  • D
    89% (16)

Why each option

FlexVPN is an IKEv2-based VPN framework, making the IKEv2 profile a mandatory configuration element to establish any FlexVPN tunnel.

AEAP configuration

EAP is an optional authentication method that may be used within an IKEv2 profile, but it is not a required construct for every FlexVPN deployment.

Bmultipoint GRE tunnel interface

Multipoint GRE tunnel interfaces are associated with DMVPN, not a required component of FlexVPN tunnels.

CIKEv1 policy

FlexVPN is built exclusively on IKEv2; IKEv1 policies are incompatible with the FlexVPN framework.

DIKEv2 profileCorrect

FlexVPN exclusively uses IKEv2 as its key management protocol, and the IKEv2 profile is a required construct that ties together authentication methods, authorization policies, and virtual template interfaces. Without an IKEv2 profile, the router cannot map inbound IKEv2 negotiations to the correct tunnel parameters. All other FlexVPN components depend on this profile being defined.

Concept tested: FlexVPN mandatory IKEv2 profile requirement

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ikevpn/configuration/xe-3s/sec-flex-vpn-xe-3s-book.html

Topics

#FlexVPN#IKEv2 profile#tunnel configuration#required construct

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice