ETExamTower
Q16Troubleshooting using ASDM and CLIMultiple answers

Which two commands help identify why the NHRP registration process is still incomplete even though the IPsec tunnel is up? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
D
50% (7)
E
36% (5)
A
7% (1)
C
7% (1)
B
0% (0)
Discussion · 21
7
D AND E my friends. IPsec is already up, so isakmp(phase 1) is too.
5
WHY NOT D & E
D, E 5
Selected Answer: DE IPsec process is complete, so that rules out all crypto vpn related commands. You need to look at NHRP next. Which commands are left that produce nhrp outputs? D and E
4
Correct Answer: D,E Explanation: Ipsec tunnel is up so we don’t need to troubleshoot that (so we don’t need option A and C here) Option B (show ip traffic) is completely unrelated here. This leaves us with D and E which are both helping us troubleshoot the DMVPN NHRP registration process.
D, E 4
Selected Answer: DE D and E are the only relevant commands here
4
Answer correct is DE https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-per-tunnel-qos.html
3
Correct Answers: A,D https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html
A, D 3
Selected Answer: AD basically you need the show crypto isakmp sa to see the decaps and decrypt packets : #pkts encaps: 154, #pkts encrypt: 154, #pkts digest: 154 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0
D, E 3
Selected Answer: DE DE is the most correct answer
3
I meant C and D
2
the correct answer is A and D
2
Ipsec might be up but this does not mean the encap/decap counter is fine. So u need to check decap/encap counter and NHRP: So A & D
2
DE are the correct answer
2
your link shows that correct answer is C and D Router#show crypto IPSEC sa local ident (addr/mask/prot/port): (172.16.1.1/255.255.255.255/47/0) remote ident (addr/mask/prot/port): (172.17.0.1/255.255.255.255/47/0) #pkts encaps: 154, #pkts encrypt: 154, #pkts digest: 154 #pkts decaps: 0, #pkts decrypt: 0, #pkts verify: 0 inbound esp sas: spi: 0xF830FC95(4163959957) outbound esp sas: spi: 0xD65A7865(3596253285) !--- !--- Output is truncated !--- It shows that return traffic does not come back from the other end of the tunnel. Check NHS entry in the spoke router: Router#show ip nhrp nhs detail Legend: E=Expecting replies, R=Responding Tunnel0: 172.17.0.1 E req-sent 0 req-failed 30 repl-recv 0 Pending Registration Requests: Registration Request: Reqid 4371, Ret 64 NHS 172.17.0.1
C, D 2
Selected Answer: CD So, options C and D are the right answers: show crypto ipsec sa and show ip nhrp traffic. Option A, show crypto isakmp sa, shows the status of the ISAKMP security associations, which are used to build the IPsec SA. Option B, show ip traffic, shows traffic statistics for different protocols, but does not give specific information about IPsec or NHRP traffic. Option E, show dmvpn detail, gives detailed information about the DM VPN configuration, including the status of the IPsec and NHRP components, but is not as specific as the other two commands in finding the cause of the NHRP registration issue.
1
I mean A and E. not D
1
This one right here, straight from the horse's mouth. Here's the link straight to the relevant section: https://www.cisco.com/c/en/us/support/docs/security/dynamic-multipoint-vpn-dmvpn/111976-dmvpn-troubleshoot-00.html#verifynhrpreg
1
A is not correct because the IPsec tunnel is already formed
1
That's show ipsec sa, not isakmp.
1
'A and D' looks to be correct.
D, E 1
Selected Answer: DE Correct answers: ✅ D. show ip nhrp traffic ✅ E. show dmvpn detail Dave#271 Explanation: The question clearly says the IPsec tunnel is already up, but the NHRP registration is still not finishing. So IKE/IPsec verification commands are not helpful for this case. show ip nhrp traffic Shows whether NHRP packets (requests and replies) are being sent and received. If the counters are not going up, the issue is definitely inside the NHRP process (NHS, authentication, mapping). show dmvpn detail The most useful DMVPN troubleshooting command. It shows: NHRP registration status NHS information Tunnel and IPsec state in one output This makes it ideal for finding why NHRP registration is failing. Why the other options are incorrect: A. show crypto isakmp sa Only checks IKE status; IPsec is already established. B. show ip traffic Too broad and does not give NHRP-specific insight. C. show crypto ipsec sa Confirms IPsec SAs, not NHRP registration.