exam questions

Exam 300-730 All Questions

View all questions & answers for the 300-730 exam

Exam 300-730 topic 1 question 170 discussion

Actual exam question from Cisco's 300-730
Question #: 170
Topic #: 1
[All 300-730 Questions]

An organization wants to implement a site-to-site VPN solution that must be able to support 350 sites with direct communications between all sites, fully encrypt the packet header and payload, and support propagation of routing information over IPsec. Which solution meets these requirements?

  • A. IPsec full mesh
  • B. DMVPN
  • C. GETVPN
  • D. FlexVPN
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
brian7857ffs45
Highly Voted 1 year, 9 months ago
Selected Answer: D
Thinking D. "support propagation of routing information over IPsec" Sounds like Route Injection via IKEv2 Authorization. This is supported through FlexVPN
upvoted 7 times
Veliion
1 year, 5 months ago
I think your logic is correct. https://networklessons.com/cisco/ccie-enterprise-infrastructure/flexvpn-ikev2-routing
upvoted 2 times
...
...
pfrank
Most Recent 9 months, 1 week ago
Selected Answer: B
DMVPN supports Hub-and-spoke with spoke-to-spoke while FlexVPN does not support spoke-to-spoke. Pg. 37 Table 2-3 Comparing VPN options, CCNP SVPN 300-730 Official Cert Guide.
upvoted 4 times
...
kylesam2017
10 months, 2 weeks ago
"B" DMVPN is the correct answer: For the specified requirements of supporting 350 sites with direct communications between all sites, fully encrypting the packet header and payload, and supporting the propagation of routing information over IPsec, the appropriate solution would be DMVPN (Dynamic Multipoint Virtual Private Network). DMVPN is designed to provide scalable and efficient site-to-site VPNs. It supports dynamic creation of direct tunnels between sites, fully encrypts packet header and payload using IPsec, and allows for the propagation of routing information over the VPN tunnels. FlexVPN, while a versatile VPN solution, is not specifically tailored for the dynamic creation of multipoint VPNs like DMVPN. DMVPN is well-suited for scenarios where you have a large number of sites that need to communicate with each other directly. Therefore, the recommended solution for the specified requirements is DMVPN.
upvoted 2 times
...
JKPippers
1 year, 1 month ago
In my opinion the best answer is B because the question require a "direct communications between all site" and it is possible to use IPSEC as explained in the link below: https://networklessons.com/cisco/ccie-routing-switching/dmvpn-over-ipsec#IPsec
upvoted 1 times
...
spambox730
1 year, 4 months ago
Selected Answer: D
A. IPsec full mesh --> Does not scale well to 350 routers fully meshed. B. DMVPN --> Does everything, except the routing in IPSec. C. GETVPN --> Does everything, except the IP header encryption. It copies the original header. D. FlexVPN --> This covers all requirements. (It is also newer than the others so i assume Cisco wants to propagate it.)
upvoted 2 times
...
mpls_link
1 year, 7 months ago
Selected Answer: C
I am going with GETVPN on this, DMVPN does not support multicast, it is a NBMA network
upvoted 1 times
gondohwe
11 months, 4 weeks ago
GETVPN doesnt encapsulate the whole packet but preserves the ip headers so its not the solution wanted here bro
upvoted 2 times
...
gondohwe
1 year ago
aaah DMVPN does support multicast go read further
upvoted 1 times
...
Anonymous983475
1 year, 5 months ago
DMVPN does support multicast, you need to add the nhrp multicast mapping
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago