Q20Site-to-site Virtual Private Networks on Routers and Firewalls
In a FlexVPN hub-and-spoke topology in which spoke-to-spoke tunnels are not permitted, which command is required so that the hub can terminate FlexVPN tunnels?
← → navigate · a answer
Community votes
Discussion · 10
D 5
Selected Answer: D
A: does not make sense
B: spoke to spoke is not allowed, and this command is used for spoke to spoke
c: makes no sense
D: most correct answer, as this command is needed on the hub for hub and spoke communication.
3
I think D is right. Because Spoke-to-Spoke traffic is not allowed and wanted, so redirect is not needed. But FlexVPN uses Virtual Templates to create Virtual Access interfaces for each connected Spoke.
2
D. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/15-mt/sec-flex-vpn-15-mt-book/sec-flex-spoke.html?bookSearch=true
1
B - need too
1
"On a FlexVPN hub-and-spoke topology where spoke-to-spoke tunnels are not allowed, which command is needed for the hub"
B 1
Selected Answer: B
vote for b
1
Can you explain it please?
1
Tricky question
hub:
interface Virtual-Template1 type tunnel
ip unnumbered Loopback0
ip nhrp network-id 1
ip nhrp redirect
tunnel protection ipsec profile default
!
spoke:
!
interface Virtual-Template1 type tunnel
ip unnumbered Tunnel0
ip nhrp network-id 1
ip nhrp shortcut virtual-template 1
ip nhrp redirect
tunnel protection ipsec profile default
!
Not sure why the spoke has redirect there too.
1
here we go again....exam topic shows B which is totally a wrong answer...D is the one for this qstn...why don't the admin update this unless it's meant to create confusion...makes me wonder if this is a valid database of exam qstns
1
the question said that spoke-to-spoke traffic is not needed