352-001 · Question #111
When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)
The correct answer is C. packets per second capabilities D. maximum tunnel termination capabilities. Packets per second throughput and maximum tunnel termination count are the most accurate scalability indicators for an IPSec headend because they directly measure cryptographic forwarding capacity and concurrent session limits.
Question
When adding an IPSec headend termination device to your network design, which two performance indicators are the most accurate to determine device scalability? (Choose two.)
Options
- ACPU capabilities
- Bbandwidth capabilities
- Cpackets per second capabilities
- Dmaximum tunnel termination capabilities
How the community answered
(28 responses)- A11% (3)
- B18% (5)
- C71% (20)
Why each option
Packets per second throughput and maximum tunnel termination count are the most accurate scalability indicators for an IPSec headend because they directly measure cryptographic forwarding capacity and concurrent session limits.
CPU capability is a hardware attribute that influences performance but is not an accurate standalone scalability indicator - devices with similar CPUs can differ greatly in IPSec performance depending on hardware crypto offload engines and dedicated ASICs.
Bandwidth capability describes raw interface throughput and does not account for the per-packet cryptographic processing overhead of IPSec, making it an insufficient indicator of actual encrypted traffic scalability.
Packets per second measures the rate at which the device can encrypt, decrypt, and forward IPSec-protected traffic, directly reflecting the device's cryptographic processing capacity and where it will bottleneck under load.
Maximum tunnel termination capability defines the upper limit of concurrent IPSec sessions the device can maintain, making it the most precise metric for determining how many remote sites or clients the headend can scale to support.
Concept tested: IPSec VPN headend scalability performance indicators
Source: https://www.cisco.com/c/en/us/products/collateral/security/asr-1000-series-aggregation-services-routers/white-paper-c11-737906.html
Topics
Community Discussion
No community discussion yet for this question.