nerdexam
Cisco

352-001 · Question #452

Refer to the exhibit. You are planning a migration to a dual-stack IPv4/1Pv6 campus environment while providing a flexible and scalable design with fault isolation. The design should allow IPv6…

The correct answer is A. IPv6 ISATAP tunnel termination point C. GRE tunnel to the local Internet edge. ISATAP tunnel termination and GRE tunnels together provide the interim IPv6-over-IPv4 tunneling needed to introduce IPv6 services incrementally without a network-wide cutover.

Designing Network Infrastructure

Question

Refer to the exhibit. You are planning a migration to a dual-stack IPv4/1Pv6 campus environment while providing a flexible and scalable design with fault isolation. The design should allow IPv6 devices to tunnel over portions of the campus that are not yet natively IPv6-enabled, including wireless and voice endpoints. Your plan requires an interim approach that allows for a faster introduction of new services without requiring a network wide hot cutover. Which two services block functions meet these requirements? (Choose 2)

Exhibit

352-001 question #452 exhibit

Options

  • AIPv6 ISATAP tunnel termination point
  • Bpolicy gateways
  • CGRE tunnel to the local Internet edge
  • DBGP route reflectors
  • EGET VPN key server

How the community answered

(53 responses)
  • A
    68% (36)
  • B
    19% (10)
  • D
    9% (5)
  • E
    4% (2)

Why each option

ISATAP tunnel termination and GRE tunnels together provide the interim IPv6-over-IPv4 tunneling needed to introduce IPv6 services incrementally without a network-wide cutover.

AIPv6 ISATAP tunnel termination pointCorrect

An ISATAP tunnel termination point allows IPv6 hosts to use the existing IPv4 infrastructure as a virtual IPv6 link layer, enabling endpoints such as wireless and voice devices to reach IPv6 services even where the campus fabric is not yet natively dual-stacked.

Bpolicy gateways

Policy gateways enforce traffic policies and QoS but provide no tunneling or encapsulation mechanism to carry IPv6 over IPv4-only network segments.

CGRE tunnel to the local Internet edgeCorrect

A GRE tunnel to the Internet edge encapsulates IPv6 packets inside IPv4 headers, allowing IPv6 traffic to transit IPv4-only campus segments and reach external IPv6 destinations without requiring a simultaneous network-wide upgrade.

DBGP route reflectors

BGP route reflectors address BGP session scalability within an AS and do not provide any IPv6-over-IPv4 tunneling capability for endpoints.

EGET VPN key server

GET VPN is a group-based encryption framework for WAN traffic and has no role in tunneling IPv6 packets over non-IPv6 campus infrastructure.

Concept tested: IPv6 transition tunneling - ISATAP and GRE in campus

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6/configuration/15-mt/ipv6-15-mt-book/ip6-tunnel.html

Topics

#dual-stack migration#ISATAP#IPv6 tunneling#campus IPv6 design

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice