exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 47 discussion

Actual exam question from Cisco's 300-730
Question #: 47
Topic #: 1
[All 300-730 Questions]

Which two commands help determine why the NHRP registration process is not being completed even after the IPsec tunnel is up? (Choose two.)

  • A. show crypto isakmp sa
  • B. show ip traffic
  • C. show crypto ipsec sa
  • D. show ip nhrp traffic
  • E. show dmvpn detail
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
YourFriendlyNeighborhoodSpider
Highly Voted 2 years, 9 months ago
D AND E my friends. IPsec is already up, thus isakmp(phase 1) as well.
upvoted 6 times
...
brian7857ffs45
Highly Voted 1 year, 9 months ago
Selected Answer: DE
IPsec process is complete so that rules out all crypto vpn related commands. You need to look at NHRP next. Which commands are left that produce nhrp outputs? D and E
upvoted 5 times
...
pfrank
Most Recent 9 months, 1 week ago
Selected Answer: CD
Therefore, options C and D are the correct answers: show crypto ipsec sa and show ip nhrp traffic. Option A, show crypto isakmp sa, displays the status of the ISAKMP security associations, which are used to establish the IPsec SA. Option B, show ip traffic, displays traffic statistics for various protocols, but does not provide specific information about IPsec or NHRP traffic. Option E, show dmvpn detail, provides detailed information about the DM VPN configuration, including the status of the IPsec and NHRP components, but is not as specific as the other two commands in identifying the cause of the NHRP registration issue.
upvoted 2 times
...
kylesam2017
10 months, 4 weeks ago
'A and D' seems to be correct.
upvoted 1 times
...
Rosh8787
11 months, 1 week ago
DE are the correct answer
upvoted 2 times
...
JKPippers
1 year ago
Answer correct is DE https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-per-tunnel-qos.html
upvoted 4 times
...
mihaid
1 year, 4 months ago
Ipsec might be up but this not asure the encap/decap counter is fine. So u need to check decap/encap counter and NHRP: So A & D
upvoted 2 times
mihaid
1 year, 3 months ago
I ment C and D
upvoted 3 times
...
...
mpls_link
1 year, 7 months ago
Selected Answer: DE
DE is the most correct answer
upvoted 3 times
mpls_link
1 year, 6 months ago
A is not correct since the IPsec tunnel is already formed
upvoted 1 times
...
...
Net4dd
1 year, 9 months ago
Selected Answer: DE
D and E are the only one relevant commands here
upvoted 4 times
...
red_sparrow_Gr
1 year, 9 months ago
Selected Answer: AD
basically you need the show crypto isakmp sa to see the decaps and decrypt packets : #pkts encaps: 154, #pkts encrypt: 154, #pkts digest: 154 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
upvoted 3 times
...
johnd47
1 year, 11 months ago
Correct Answers: A,D https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html
upvoted 3 times
netizen937
1 year, 8 months ago
This one right here, straight from the horse's mouth. Here's the link straight to the relevant section: https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html#verifynhrpreg
upvoted 1 times
...
starletka
10 months, 2 weeks ago
your link shows that correct answer is C and D Router#show crypto IPSEC sa local ident (addr/mask/prot/port): (172.16.1.1/255.255.255.255/47/0) remote ident (addr/mask/prot/port): (172.17.0.1/255.255.255.255/47/0) #pkts encaps: 154, #pkts encrypt: 154, #pkts digest: 154 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 inbound esp sas: spi: 0xF830FC95(4163959957) outbound esp sas: spi: 0xD65A7865(3596253285) !--- !--- Output is truncated !--- It shows that return traffic does not come back from the other end of the tunnel. Check NHS entry in the spoke router: Router#show ip nhrp nhs detail Legend: E=Expecting replies, R=Responding Tunnel0: 172.17.0.1 E req-sent 0 req-failed 30 repl-recv 0 Pending Registration Requests: Registration Request: Reqid 4371, Ret 64 NHS 172.17.0.1
upvoted 2 times
...
...
ScaX
2 years ago
Correct Answer: D,E Explanation: Ipsec tunnel is up so we don’t need to troubleshoot that (so we don’t need option A and C here) Option B (show ip traffic) is totally unrelated here. This leave us with D and E which are indeed both helping us to troubleshoot DMVPN NHRP registration process.
upvoted 4 times
spambox730
1 year, 4 months ago
That's show ipsec sa not isakmp.
upvoted 1 times
...
...
Carlj007
2 years, 11 months ago
I mean A and E. not D
upvoted 1 times
...
Carlj007
2 years, 11 months ago
the correct answer is A and D
upvoted 2 times
...
abd123
3 years, 2 months ago
WHY NOT D & E
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...