exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 32 discussion

Actual exam question from Cisco's 300-730
Question #: 32
Topic #: 1
[All 300-730 Questions]

An engineer is troubleshooting a new DMVPN setup on a Cisco IOS router. After the show crypto isakmp sa command is issued, a response is returned of
"MM_NO_STATE." Why does this failure occur?

  • A. The ISAKMP policy priority values are invalid.
  • B. ESP traffic is being dropped.
  • C. The Phase 1 policy does not match on both devices.
  • D. Tunnel protection is not applied to the DMVPN tunnel.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
nospampls
2 months ago
Selected Answer: C
should be C A show crypto isakmp sa command shows the ISAKMP SA to be inMM_NO_STATE. This also means that main mode has failed. dst src state conn-id slot 10.1.1.2 10.1.1.1 MM_NO_STATE 1 0 Verify that the phase 1 policy is on both peers, and ensure that all the attributes match. https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html#toc-hId--70669866
upvoted 1 times
...
joegreen
10 months, 1 week ago
Selected Answer: C
Answer is C. ISAKMP packets would be dropped if it were the case, not ESP packets.
upvoted 1 times
...
starletka
1 year, 3 months ago
Selected Answer: C
phase 1 failed so non matching. human error is always first asumption
upvoted 1 times
...
kylesam2017
1 year, 4 months ago
"C" is the correct answer here.
upvoted 1 times
...
gondohwe
1 year, 6 months ago
policy not matching e.g authentication key....go for C
upvoted 1 times
...
mihaid
1 year, 8 months ago
Selected Answer: B
B- is also correct , this should be the first assumption if no other details were given C- is also correct , but this should be the 2nd assumption ?
upvoted 1 times
jimmyjose
1 year, 1 month ago
Answer options B & D are for phase 2, hence, they are ruled out. Out of options A & C, answer seems to be C because phase 1 denotes main mode, which has no state as per the error message - 'MM_NO_STATE'.
upvoted 1 times
...
...
Khs01
1 year, 10 months ago
Selected Answer: C
C is correct
upvoted 1 times
...
Anonymous983475
1 year, 11 months ago
Selected Answer: C
Phase 1 failed
upvoted 1 times
...
Net4dd
2 years, 2 months ago
Selected Answer: C
C is the one logical MM is for main mode
upvoted 1 times
...
Dante8880
2 years, 5 months ago
ISAKMP SA has been created but not built. https://www.tunnelsup.com/isakmp-ike-phase-1-status-messages/
upvoted 1 times
...
Backupz
2 years, 5 months ago
Selected Answer: C
correct answer is C
upvoted 1 times
...
LouisVuitton
2 years, 6 months ago
Selected Answer: C
Correct answer is C
upvoted 1 times
...
mazinhoo
2 years, 9 months ago
Correct answer is C https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html
upvoted 1 times
...
nospampls
3 years, 1 month ago
Selected Answer: C
like Slysloth wrote C should be right
upvoted 1 times
...
Carlj007
3 years, 4 months ago
correct answer is C
upvoted 4 times
...
shiznity2k
4 years, 2 months ago
C is the correct answer, it is due to policy mismatch for phase 1
upvoted 2 times
...
Slysloth
4 years, 4 months ago
Could also be a mismatch on both sides as stated in this troubleshooting guide. https://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409-ipsec-debug-00.html Though it is mentioned that its DMVPN so that could be why esp is being dropped but that should only be if protection is on.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago