Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam 350-401 topic 1 question 89 discussion

Actual exam question from Cisco's 350-401
Question #: 89
Topic #: 1
[All 350-401 Questions]


Refer to the exhibit. A network engineer must simplify the IPsec configuration by enabling IPsec over GRE using IPsec profiles. Which two configuration changes accomplish this? (Choose two).

  • A. Create an IPsec profile, associate the transform-set ACL, and apply the profile to the tunnel interface.
  • B. Apply the crypto map to the tunnel interface and change the tunnel mode to tunnel mode ipsec ipv4.
  • C. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL.
  • D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface.
  • E. Remove the crypto map and modify the ACL to allow traffic between 10.10.0.0/24 to 10.20.0.0/24.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
xziomal9
Highly Voted 2 years, 7 months ago
The correct answer is: C. Remove all configuration related to crypto map from R1 and R2 and eliminate the ACL. D. Create an IPsec profile, associate the transform-set, and apply the profile to the tunnel interface.
upvoted 13 times
Eddgar0
2 years ago
You are right if is simplifying configuration the cryptomap is not needed when using ipsec profile.
upvoted 1 times
...
iAbdullah
2 years, 6 months ago
you right because we dont have to chabnge the mode in tunnel > and we have to delete the acl..
upvoted 2 times
...
...
Hamzaaa
Highly Voted 3 years ago
C&D are the correct choices since, IP-sec doesn't need crypto map to operate, and there is no Ip-sec profile, it must be created
upvoted 7 times
...
wr4net
Most Recent 11 months, 2 weeks ago
a somewhat easy cheatsheet for the exam: you need 1 "remove" and 1 "IPSec profile." this rules out B right away there is no transform set ACL, so that kills A the ACL is technically a GRE ACL on outside interface. so you are left with D as the "IPSec profile." then whatever you do, it will be on both routers due to vpn symmetry in configs So that rules out E, since it doesnt reference both routers. So you are left with C as he "remove"
upvoted 1 times
...
HungarianDish
1 year ago
https://networklessons.com/cisco/ccie-routing-switching-written/ipsec-static-virtual-tunnel-interface https://study-ccnp.com/site-to-site-virtual-tunnel-interface-vti-over-ipsec/
upvoted 1 times
...
Wooker
1 year, 9 months ago
Selected Answer: CD
C and D are correct.
upvoted 1 times
...
Pudu_vlad
1 year, 10 months ago
C and D is correct
upvoted 1 times
...
Aldebeer
2 years ago
Selected Answer: CD
These are correct answers..
upvoted 1 times
...
Eddgar0
2 years ago
Selected Answer: CD
C & D have more sense, because the question ask for simplify config. So Removing al Cryptomap config and the ACL tied to it, also applying that to the tunnel using the tunnel protection command. B does not make sense as is calling for simplifying so using cryptomap on tunnels does not simplify and make ip sec profile useless.
upvoted 2 times
...
aohashi
2 years, 2 months ago
Selected Answer: CD
It should be CD
upvoted 1 times
...
zzmejce
2 years, 2 months ago
Selected Answer: CD
C and D are correct.
upvoted 2 times
...
Net91
2 years, 4 months ago
C,D correct
upvoted 2 times
...
wwwwaaaa
2 years, 4 months ago
I think the answer is correct I dont understand the need to remove ACL, it is there but not in the way
upvoted 1 times
...
sharon90
2 years, 4 months ago
i wonder why the admin ignores us instead of editing the proper answers which are C and D.
upvoted 2 times
...
cyrus777
2 years, 5 months ago
C&D makes more sense
upvoted 1 times
...
error_909
2 years, 7 months ago
Answer B can only be used to configure GRE Tunnel over an IPsec Tunnel and in this case, we don't need an IPsec profile just the crypto-map. But in the question, we want to configure IPsec over a GRE Tunnel, so in this case, we need the following for IKE phase1 and IKE phase 2: 1- crypto isakmp policy 2- crypto isakmp key "in case of a pre-shared key defined in policy" 3- crypto isakmp transform-set 4- crypto ipsec profile. Go to Interface: -tunnel)# tunnel mode ipsec [ipv4/ipv6] -tunnel)# tunnel protection ipsec profile [profile-Name]
upvoted 6 times
...
HK010
2 years, 9 months ago
C D. "change the tunnel mode to tunnel mode IPsec ipv4." it's actually regarding Site-to-Site VTI over IPsec, not enabling IPsec over GRE using IPsec. page 462
upvoted 3 times
...
DaniOcampo1992
2 years, 10 months ago
C&D are correct but I think the tunnel mode ipsec ipv4 command should also be applied for the configuration to be complete.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...