300-730 · Question #87
A company's remote locations connect to the data centers via MPLS. A new request requires that unicast and multicast traffic that exits in the remote locations be encrypted. Which non-tunneled…
The correct answer is D. GETVPN. GETVPN is the only non-tunneled VPN solution that can encrypt both unicast and multicast traffic while preserving original IP headers over an existing MPLS infrastructure.
Question
Options
- ASSL
- BFlexVPN
- CDMVPN
- DGETVPN
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C13% (4)
- D81% (25)
Why each option
GETVPN is the only non-tunneled VPN solution that can encrypt both unicast and multicast traffic while preserving original IP headers over an existing MPLS infrastructure.
SSL VPN creates an encrypted application-layer tunnel and does not support multicast traffic encryption, nor does it qualify as a non-tunneled technology.
FlexVPN uses IKEv2 to create IPsec tunnels, making it a tunneling technology that does not meet the non-tunneled requirement.
DMVPN uses GRE tunnels encapsulated with IPsec, which adds tunnel headers and disqualifies it as a non-tunneled technology.
GETVPN (Group Encrypted Transport VPN) encrypts traffic using IPsec while preserving the original source and destination IP addresses, making it non-tunneled by design. It natively supports multicast encryption, which tunneling-based technologies cannot provide, and is specifically architected for deployment over MPLS networks where routing infrastructure already exists. These characteristics satisfy both the non-tunneled requirement and the need to encrypt multicast traffic from remote locations.
Concept tested: GETVPN non-tunneled multicast encryption over MPLS
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_getvpn/configuration/xe-16/sec-get-vpn-xe-16-book.html
Topics
Community Discussion
No community discussion yet for this question.