i tested every answer in my lab and this is my finding.
- only when a tunnel interface is used crypto map tag is Tunnel1-head-0
- only when tunnel mode is ipsec the local and remote ident are 0.0.0.0/0.0.0.0/0/0
- as soon as gre is used local and remote ident are (15.1.1.1/255.255.255.255/47/0)
so i would choose D (FlexVPN with sVTI) and E (VTI when configured static)
2,5 years later i do my re-cert and i am still confinced thatd D and E are correct
DMVPN usese Gre and would show (0.0.0.0/0.0.0.0/47/0)
DMVPN is not possible with IPsec
execuse me ? FlexVPN has Tunnel configuration as well. is you use GRE the NHRP will work and allow spoke-spoke , if you turn it as IPsec mode you will lose spoke-spoke and only hub-spoke will allow
I got those results from LAB, only for DMVPN and VTI. VlexVPN has Virtual-access interface, NOT Tunnel interface. GRE-only tunnel doesnt use IPSEC so it wont show up in IPSEC SA command and Crypto map is not used for tunnel interfaces.
for whoever tested it in the lab, For flexvpn the output of show crypto ipsec sa, starts with the following:
CSR1#show crypto ipsec sa
interface: Virtual-Access // not interface: Tunnel0
So it should be B and E
You are correct about the name of the interface but I have not been able to recreate an ipsec SA with DMVPN where the x.x.x.x/x.x.x.x/47/0 port 47 is not showing
I built this in a lab and concur with nospampls results.
Note that "show crypto ipsec sa" on a DMVPN will show port 47 as it is using mGRE. VTI with IKEv2 produces the 0.0.0.0/0.0.0.0/0/0 output as shown in the example. Since the question is asking for "tunnel" type that means only possible answers are D and E
Should be A and E, there is no reference to protocol 47 (GRE) in the output. Also the output shows acl, which implies crypto map. All of the local and remote idents are "0", indicating raw IPsec.
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.300-730 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
nospampls
Highly Voted 3 years agonospampls
2 months agoNullNull88
2 years, 7 months agomihaid
1 year, 8 months agoMJexy
Highly Voted 3 years, 10 months agoz6st2a1jv
Most Recent 10 months, 2 weeks agoJKPippers
1 year, 5 months agomarges
1 year, 9 months agomarges
1 year, 9 months agoAnonymous983475
1 year, 11 months agoAnonymous983475
1 year, 11 months agoAnonymous983475
1 year, 11 months agoAnonymous983475
1 year, 11 months agoNet4dd
2 years, 2 months agored_sparrow_Gr
2 years, 3 months agobrian7857ffs45
2 years, 2 months agobrian7857ffs45
2 years, 3 months agoNullNull88
2 years, 7 months agocs51
2 years, 10 months agocisco_guy
4 years, 3 months ago