300-730 · Question #62
Refer to the exhibit. What is a result of this configuration?
The correct answer is A. Spoke 1 fails the authentication because the authentication methods are incorrect. In this hub-and-spoke IKE configuration, Spoke 1 fails authentication because its configured IKE authentication methods do not match what the hub expects, preventing phase 1 from completing.
Question
Options
- ASpoke 1 fails the authentication because the authentication methods are incorrect.
- BSpoke 2 passes the authentication to the hub and successfully proceeds to phase 2.
- CSpoke 2 fails the authentication because the remote authentication method is incorrect.
How the community answered
(38 responses)- A66% (25)
- B21% (8)
- C13% (5)
Why each option
In this hub-and-spoke IKE configuration, Spoke 1 fails authentication because its configured IKE authentication methods do not match what the hub expects, preventing phase 1 from completing.
Spoke 1 is configured with an IKE authentication method (such as pre-shared key vs. RSA signature) that does not align with the hub's IKE policy, causing phase 1 negotiation to fail at the authentication exchange step. Because IKE phase 1 must complete before phase 2 can begin, Spoke 1 cannot establish an IPsec security association or pass traffic. This type of mismatch is a common misconfiguration in DMVPN deployments where spokes have differing auth settings.
Spoke 2 does not successfully proceed to phase 2 because the exhibit shows a configuration issue that disrupts the authentication process, making a successful phase 2 outcome incorrect.
The authentication failure belongs to Spoke 1, not Spoke 2; the exhibit does not indicate that Spoke 2 has an incorrect remote authentication method.
Concept tested: IKE phase 1 authentication method mismatch in DMVPN
Source: https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/97210-dmvpn-config.html
Topics
Community Discussion
No community discussion yet for this question.