Free Cisco® 300-730 Exam Questions (page: 9)

Refer to the exhibit. An engineer is troubleshooting a new GRE over IPsec tunnel. The tunnel is established, but the engineer cannot ping from spoke 1 to spoke 2. Which type of traffic is being blocked?

  1. ESP packets from spoke2 to spoke1
  2. ISAKMP packets from spoke2 to spoke1
  3. ESP packets from spoke1 to spoke2
  4. ISAKMP packets from spoke1 to spoke2

Answer(s): A



Which command is used to troubleshoot an IPv6 FlexVPN spoke-to-hub connectivity failure?

  1. show crypto ikev2 sa
  2. show crypto isakmp sa
  3. show crypto gkm
  4. show crypto identity

Answer(s): A


Reference:

https://www.cisco.com/c/en/us/support/docs/security/flexvpn/116413-configure-flexvpn-00.pdf



In a FlexVPN deployment, the spokes successfully connect to the hub, but spoke-to-spoke tunnels do not form. Which troubleshooting step solves the issue?

  1. Verify the spoke configuration to check if the NHRP redirect is enabled.
  2. Verify that the spoke receives redirect messages and sends resolution requests.
  3. Verify the hub configuration to check if the NHRP shortcut is enabled.
  4. Verify that the tunnel interface is contained within a VRF.

Answer(s): B


Reference:

https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-summ-maps.pdf



An engineer is troubleshooting a new DMVPN setup on a Cisco IOS router. After the show crypto isakmp sa command is issued, a response is returned of "MM_NO_STATE." Why does this failure occur?

  1. The ISAKMP policy priority values are invalid.
  2. ESP traffic is being dropped.
  3. The Phase 1 policy does not match on both devices.
  4. Tunnel protection is not applied to the DMVPN tunnel.

Answer(s): C


Reference:

https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html






Post your Comments and Discuss Cisco® 300-730 exam prep with other Community members:

300-730 Exam Discussions & Posts