ETExamTower
Q20Site-to-site Virtual Private Networks on Routers and Firewalls

In a FlexVPN hub-and-spoke topology in which spoke-to-spoke tunnels are not permitted, which command is required so that the hub can terminate FlexVPN tunnels?

← → navigate · a answer
Community votes
B
67% (2)
D
33% (1)
A
0% (0)
C
0% (0)
Discussion · 10
D 5
Selected Answer: D A: does not make sense B: spoke to spoke is not allowed, and this command is used for spoke to spoke c: makes no sense D: most correct answer, as this command is needed on the hub for hub and spoke communication.
3
I think D is right. Because Spoke-to-Spoke traffic is not allowed and wanted, so redirect is not needed. But FlexVPN uses Virtual Templates to create Virtual Access interfaces for each connected Spoke.
2
D. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/15-mt/sec-flex-vpn-15-mt-book/sec-flex-spoke.html?bookSearch=true
1
B - need too
1
"On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub"
B 1
Selected Answer: B vote for b
1
Can you explain it please?
1
Tricky question hub: interface Virtual-Template1 type tunnel ip unnumbered Loopback0 ip nhrp network-id 1 ip nhrp redirect tunnel protection ipsec profile default ! spoke: ! interface Virtual-Template1 type tunnel ip unnumbered Tunnel0 ip nhrp network-id 1 ip nhrp shortcut virtual-template 1 ip nhrp redirect tunnel protection ipsec profile default ! Not sure why the spoke has redirect there too.
1
here we go again....exam topic shows B which is totally a wrong answer...D is the one for this qstn...why don't the admin update this unless it's meant to create confusion...makes me wonder if this is a valid database of exam qstns
1
the question said that spoke-to-spoke traffic is not needed