nerdexam
Cisco

400-007 · Question #40

You have been tasked with designing a data center interconnect to provide business continuity. You want to encrypt the traffic over the DCI using IEEE 802.1AE MACsec to prevent the deployment of any…

The correct answer is A. EoMPLS E. KVPLS. MACsec (IEEE 802.1AE) operates at Layer 2 and requires the transport technology to preserve the Ethernet frame structure end-to-end; only Layer 2 MPLS-based DCI technologies satisfy this requirement.

Designing Security

Question

You have been tasked with designing a data center interconnect to provide business continuity. You want to encrypt the traffic over the DCI using IEEE 802.1AE MACsec to prevent the deployment of any firewall or IPS. Which two interconnect technologies support MACsec? (Choose two.)

Options

  • AEoMPLS
  • BMPLS Layer 3 VPN
  • CDMVPN
  • DGET VPN
  • EKVPLS

How the community answered

(35 responses)
  • A
    86% (30)
  • B
    3% (1)
  • C
    9% (3)
  • D
    3% (1)

Why each option

MACsec (IEEE 802.1AE) operates at Layer 2 and requires the transport technology to preserve the Ethernet frame structure end-to-end; only Layer 2 MPLS-based DCI technologies satisfy this requirement.

AEoMPLSCorrect

EoMPLS (Ethernet over MPLS) is a Layer 2 pseudowire service that transports native Ethernet frames across an MPLS backbone, preserving the Layer 2 header that MACsec encrypts and allowing end-to-end MACsec without requiring a firewall or IPS in the path.

BMPLS Layer 3 VPN

MPLS Layer 3 VPN operates at the IP layer and strips the original Ethernet headers before forwarding traffic, removing the Layer 2 context that MACsec depends on for encrypting frames between endpoints.

CDMVPN

DMVPN is a Layer 3 GRE/IPsec overlay that encapsulates IP packets rather than Ethernet frames, so it does not provide the Layer 2 adjacency required for MACsec to function between DCI endpoints.

DGET VPN

GET VPN is a group-based IP encryption technology that protects Layer 3 traffic and does not operate on or preserve Ethernet frames, making it fundamentally incompatible with the IEEE 802.1AE MACsec standard.

EKVPLSCorrect

KVPLS (VPLS - Virtual Private LAN Service) is a multipoint Layer 2 MPLS technology that emulates an Ethernet LAN segment over an MPLS core, maintaining the Ethernet frame structure end-to-end that MACsec requires to encrypt DCI traffic between data centers.

Concept tested: MACsec support over Layer 2 DCI transport technologies

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/macsec/configuration/xe-16/macsec-xe-16-book/macsec-overview.html

Topics

#MACsec#IEEE 802.1AE#data center interconnect#EoMPLS

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice