ETExamTower
Q4Troubleshooting using ASDM and CLIMultiple answers

Refer to the exhibit. Which two tunnel types generate the displayed `show crypto ipsec sa` output? *(Choose two.)*

Question exhibit
Select 2 answers.
← → navigate · a answer
Community votes
E
50% (6)
B
33% (4)
A
8% (1)
D
8% (1)
C
0% (0)
Discussion · 20
9
i tested every answer in my lab and this is what i found. - only when a tunnel interface is used crypto map tag is Tunnel1-head-0 - only when tunnel mode is ipsec the local and remote ident are 0.0.0.0/0.0.0.0/0/0 - as soon as gre is used local and remote ident are (15.1.1.1/255.255.255.255/47/0) so i would pick D (FlexVPN with sVTI) and E (VTI when configured static)
7
B and E are right. Remember crypto maps are applied to physical interfaces.
5
It asks for tunnel type. it should be C and E.
B, E 3
Selected Answer: BE for whoever tested it in the lab, For flexvpn the output of show crypto ipsec sa, begins with the following: CSR1#show crypto ipsec sa interface: Virtual-Access // not interface: Tunnel0 So it should be B and E
2
Should be A and E, there is no reference to protocol 47 (GRE) in the output. Also the output shows acl, which suggests crypto map. All of the local and remote idents are "0", which means raw IPsec.
A, E 2
Selected Answer: AE According to the lab outputs A and E are right
2
VTI#sh crypto ipsec sa interface: Tunnel0 Crypto map tag: Tunnel0-head-0, local addr 10.10.10.2 protected vrf: (none) local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0) remote ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0) current_peer 12.12.12.2 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 10.10.10.2, remote crypto endpt.: 12.12.12.2 plaintext mtu 1500, path mtu 1500, ip mtu 1500, ip mtu idb Ethernet0/0 current outbound spi: 0x0(0) PFS (Y/N): N, DH group: none
2
FlexVPN-Client#sh crypto ipsec sa interface: Tunnel0 Crypto map tag: Tunnel0-head-0, local addr 200.1.10.2 protected vrf: (none) local ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0) remote ident (addr/mask/prot/port): (0.0.0.0/0.0.0.0/0/0) current_peer 200.1.10.1 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 200.1.10.2, remote crypto endpt.: 200.1.10.1 plaintext mtu 1438, path mtu 1500, ip mtu 1500, ip mtu idb GigabitEthernet1/0 current outbound spi: 0xA9A19C6B(2845940843) PFS (Y/N): N, DH group: none
B, E 2
Selected Answer: BE I got those results from LAB, only for DMVPN and VTI. VlexVPN has Virtual-access interface, NOT Tunnel interface. GRE-only tunnel doesnt use IPSEC so it wont show up in IPSEC SA command and Crypto map is not used for tunnel interfaces.
1
crypto map is NOT a "tunnel type",. DMVPN and GETVPN are VPN types, Not Tunnel Types
1
FlexVPN is a Tunnel?
D, E 1
Selected Answer: DE I built this in a lab and agree with nospampls results. Note that "show crypto ipsec sa" on a DMVPN will show port 47 as it is using mGRE. VTI with IKEv2 produces the 0.0.0.0/0.0.0.0/0/0 output as shown in the example. Since the question asks for "tunnel" type that means only possible answers are D and E
1
You are right about the interface name but I have not been able to reproduce an ipsec SA with DMVPN where the x.x.x.x/x.x.x.x/47/0 port 47 is not showing
B, E 1
Selected Answer: BE DMVPN#sh crypto ipsec sa interface: Tunnel0 Crypto map tag: Tunnel0-head-0, local addr 209.165.201.2 protected vrf: (none) local ident (addr/mask/prot/port): (209.165.201.2/255.255.255.255/47/0) remote ident (addr/mask/prot/port): (192.0.2.3/255.255.255.255/47/0) current_peer 192.0.2.3 port 500 PERMIT, flags={origin_is_acl,} #pkts encaps: 3, #pkts encrypt: 3, #pkts digest: 3 #pkts decaps: 3, #pkts decrypt: 3, #pkts verify: 3 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 209.165.201.2, remote crypto endpt.: 192.0.2.3 plaintext mtu 1458, path mtu 1500, ip mtu 1500, ip mtu idb (none) current outbound spi: 0xD1325E27(3509739047) PFS (Y/N): N, DH group: none
1
GRE-CRYPTO-MAP#sh crypto ipsec sa interface: Ethernet0/0 Crypto map tag: OUTSIDE-MAP, local addr 10.10.10.2 protected vrf: (none) local ident (addr/mask/prot/port): (192.168.1.0/255.255.255.0/0/0) remote ident (addr/mask/prot/port): (192.168.2.0/255.255.255.0/0/0) current_peer 12.12.12.2 port 500 PERMIT, flags={origin_is_acl,ipsec_sa_request_sent} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 10.10.10.2, remote crypto endpt.: 12.12.12.2 plaintext mtu 1500, path mtu 1500, ip mtu 1500, ip mtu idb Ethernet0/0 current outbound spi: 0x0(0) PFS (Y/N): N, DH group: none
1
GETVPN#sh crypto ipsec sa interface: Ethernet0/0 Crypto map tag: GVPN-MAP, local addr 172.16.10.2 protected vrf: (none) local ident (addr/mask/prot/port): (10.0.0.0/255.252.0.0/0/0) remote ident (addr/mask/prot/port): (10.0.0.0/255.252.0.0/0/0) Group: GROUP5 current_peer 0.0.0.0 port 848 PERMIT, flags={} #pkts encaps: 0, #pkts encrypt: 0, #pkts digest: 0 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 #pkts compressed: 0, #pkts decompressed: 0 #pkts not compressed: 0, #pkts compr. failed: 0 #pkts not decompressed: 0, #pkts decompress failed: 0 #send errors 0, #recv errors 0 local crypto endpt.: 172.16.10.2, remote crypto endpt.: 0.0.0.0 plaintext mtu 1438, path mtu 1500, ip mtu 1500, ip mtu idb Ethernet0/0 current outbound spi: 0x3665FF29(912654121) PFS (Y/N): N, DH group: none
1
D and E are right. This output is from a Cisco FlexVPN client/server setup. This is the client side with VTI !!!!
1
execuse me ? FlexVPN has Tunnel configuration as well. if you use GRE the NHRP will work and allow spoke-spoke , if you set it to IPsec mode you will lose spoke-spoke and only hub-spoke will be allowed
1
Analysing the result of the command 'show crypto ipsec sa', I got the same result for both Flexvpn and DMVPN. Therefore the correct answer is BD
1
2,5 years later i do my re-cert and i am still convinced that D and E are right DMVPN usese Gre and would show (0.0.0.0/0.0.0.0/47/0) DMVPN is not possible with IPsec