exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 99 discussion

Actual exam question from Cisco's 300-730
Question #: 99
Topic #: 1
[All 300-730 Questions]

A DMVPN spoke is configured with IKEv1 to secure the tunnel. Despite having a configuration similar to other working spokes, the tunnel is not coming up. Packet captures on the spoke show packets leaving the spoke router, but not making it to the hub router. Which solution resolves this issue?

  • A. Configure the spoke and hub to use the same IKE version.
  • B. Ensure that devices between the hub and spoke are not blocking ESP traffic.
  • C. Ensure that devices between the hub and spoke are not blocking GRE traffic.
  • D. Enable the tunnel interface with the no shutdown command.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kylesam2017
10 months, 3 weeks ago
To resolve the issue with the DMVPN tunnel not coming up, the solution would be to ensure that devices between the hub and spoke are not blocking the GRE (Generic Routing Encapsulation) traffic. DMVPN uses GRE encapsulation to create the overlay network, and ESP (Encapsulating Security Payload) is used to secure the GRE-encapsulated packets. However, in this scenario, the packets are leaving the spoke router, but not reaching the hub router, indicating a possible blockage of GRE traffic. By ensuring that devices between the hub and spoke are not blocking GRE traffic, you allow the encapsulated packets to traverse the network and reach the intended destination. This can involve checking the configuration of any firewalls, routers, or other network devices along the path to ensure they are configured to allow GRE traffic. While it is also important to ensure that ESP traffic is not blocked to maintain secure communication, in this specific case, the issue lies with the GRE encapsulation itself. Once the GRE traffic is allowed, the DMVPN tunnel should be able to establish successfully.
upvoted 2 times
ed81044
7 months, 2 weeks ago
GRE is encapped in ESP. The network never sees the GRE packets.
upvoted 2 times
...
...
mjuarez20
11 months, 3 weeks ago
Selected Answer: B
For me... the first packet that the router should send is the IKE negotiation and then IPSEC negotiation. So I would go with B.
upvoted 2 times
...
JKPippers
1 year ago
Answer is C When DMVPN does not work, before you troubleshoot with IPsec, verify that the GRE tunnels work fine without IPsec encryption. https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html#toc-hId--121156399
upvoted 1 times
...
mpls_link
1 year, 6 months ago
Selected Answer: B
B, some devices between the hub and spoke might be blocking the ESP traffic
upvoted 2 times
...
mpls_link
1 year, 6 months ago
Selected Answer: C
the traffic is encrypted, C
upvoted 1 times
mpls_link
1 year, 6 months ago
sorry I mean B, some devices between the hub and spoke might be blocking the ESP traffic
upvoted 1 times
...
...
Net4dd
1 year, 8 months ago
Selected Answer: B
B. ESP since the traffic is encrypted. I have tested in the LAB with an ACL blocking ESP and GRE in my lab: show ip access-list Extended IP access list BlockGRE 5 deny esp any any (44 matches) 10 deny gre any any log 20 permit ip any any (1645 matches)
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago