nerdexam
Cisco

300-730 · Question #62

Refer to the exhibit. What is a result of this configuration?

The correct answer is A. Spoke 1 fails the authentication because the authentication methods are incorrect. In this hub-and-spoke IKE configuration, Spoke 1 fails authentication because its configured IKE authentication methods do not match what the hub expects, preventing phase 1 from completing.

Site-to-site VPNs on Routers and Firewalls

Question

Refer to the exhibit. What is a result of this configuration?

Options

  • ASpoke 1 fails the authentication because the authentication methods are incorrect.
  • BSpoke 2 passes the authentication to the hub and successfully proceeds to phase 2.
  • CSpoke 2 fails the authentication because the remote authentication method is incorrect.

How the community answered

(38 responses)
  • A
    66% (25)
  • B
    21% (8)
  • C
    13% (5)

Why each option

In this hub-and-spoke IKE configuration, Spoke 1 fails authentication because its configured IKE authentication methods do not match what the hub expects, preventing phase 1 from completing.

ASpoke 1 fails the authentication because the authentication methods are incorrect.Correct

Spoke 1 is configured with an IKE authentication method (such as pre-shared key vs. RSA signature) that does not align with the hub's IKE policy, causing phase 1 negotiation to fail at the authentication exchange step. Because IKE phase 1 must complete before phase 2 can begin, Spoke 1 cannot establish an IPsec security association or pass traffic. This type of mismatch is a common misconfiguration in DMVPN deployments where spokes have differing auth settings.

BSpoke 2 passes the authentication to the hub and successfully proceeds to phase 2.

Spoke 2 does not successfully proceed to phase 2 because the exhibit shows a configuration issue that disrupts the authentication process, making a successful phase 2 outcome incorrect.

CSpoke 2 fails the authentication because the remote authentication method is incorrect.

The authentication failure belongs to Spoke 1, not Spoke 2; the exhibit does not indicate that Spoke 2 has an incorrect remote authentication method.

Concept tested: IKE phase 1 authentication method mismatch in DMVPN

Source: https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/97210-dmvpn-config.html

Topics

#FlexVPN#spoke authentication#IKEv2 auth methods#hub-and-spoke

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice