300-730 · Question #34
Which configuration construct must be used in a FlexVPN tunnel?
The correct answer is D. IKEv2 profile. FlexVPN is an IKEv2-based VPN framework, making the IKEv2 profile a mandatory configuration element to establish any FlexVPN tunnel.
Question
Options
- AEAP configuration
- Bmultipoint GRE tunnel interface
- CIKEv1 policy
- DIKEv2 profile
How the community answered
(18 responses)- A6% (1)
- B6% (1)
- D89% (16)
Why each option
FlexVPN is an IKEv2-based VPN framework, making the IKEv2 profile a mandatory configuration element to establish any FlexVPN tunnel.
EAP is an optional authentication method that may be used within an IKEv2 profile, but it is not a required construct for every FlexVPN deployment.
Multipoint GRE tunnel interfaces are associated with DMVPN, not a required component of FlexVPN tunnels.
FlexVPN is built exclusively on IKEv2; IKEv1 policies are incompatible with the FlexVPN framework.
FlexVPN exclusively uses IKEv2 as its key management protocol, and the IKEv2 profile is a required construct that ties together authentication methods, authorization policies, and virtual template interfaces. Without an IKEv2 profile, the router cannot map inbound IKEv2 negotiations to the correct tunnel parameters. All other FlexVPN components depend on this profile being defined.
Concept tested: FlexVPN mandatory IKEv2 profile requirement
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ikevpn/configuration/xe-3s/sec-flex-vpn-xe-3s-book.html
Topics
Community Discussion
No community discussion yet for this question.