Answer: A. Spoke 1 fails the authentication because the authentication methods are incorrect.
Why??
Hubâs profile:
authentication local rsa-sigââ hub sends a certificate
authentication remote pre-shared-key ciscoââ hub expects each spoke to authenticate with the PSK cisco
Spoke 1âs profile
authentication local rsa-sigââ Spoke 1 also sends a certificate (not the expected PSK)
authentication remote pre-shared-key ciscoââ Spoke 1 expects the hub to use the PSK, but the hub uses a certificate
Because both directions are mismatched (hub expects a PSK but receives a cert; Spoke 1 expects a PSK but receives a cert), IKEv2 authentication fails and the tunnel never reaches Phase 2.
Spoke 2 has no authentication lines at all, so the router keeps the default âpre-shared-key both-ways.â That does satisfy the hubâs expectation (remote PSK cisco), so Spoke 2 can authenticate successfully.
Hub local rsa-sig remote:psk
Spoke 1 local: rsa-sig remote: psk
Spoke 2 local: psk remote: rsa-sig
C is not correct bcs Hub and Spoke2's PSK does not match, but authentication method is correct
Hence, A is correct
This section is not available anymore. Please use the main Exam Page.300-730 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
r3spu
1Â month, 2Â weeks agoDaeIsBae
1Â year, 7Â months agoshadow2020
1Â year, 1Â month agompls_link
1Â year, 10Â months ago