Q65Network Security
A network engineer must choose a VPN type that delivers the strictest security, multiple security associations for connections, and efficient VPN establishment while consuming the least bandwidth. Why should the engineer choose either FlexVPN or DMVPN for this environment?
← → navigate · a answer
Community votes
Discussion · 9
6
IKEv2 Multi-SA
The IKEv2 Multi-SA feature lets an IKEv2 Dynamic Virtual Tunnel Interface (DVTI) session on the IKEv2 responder support multiple IPsec Security Associations (SA). The maximum number of IPsec SAs per DVTI session is either pulled from AAA authorization or set on the IPsec profile. The AAA value takes higher priority. Any change to the max-flow-limit argument in the IPsec profile is not applied to the current session, but it is applied to later sessions. The IKEv2 Multi-SA feature makes the IKEv2 profile configuration in the IPsec profile optional. This optional setup allows IPsec DVTI sessions using the same virtual template to use different IKEv2 profiles, which saves the number of virtual template configurations.
Note
The IKEv2 Multi-SA feature allows multiple IPsec SAs that have non-any-any proxies. However, when the IPsec SA proxies are any-any, only a single IPsec SA is allowed.
For more information, see the “Multi-SA Support for Dynamic Virtual Tunnel Interfaces for IKEv2” module in the Security for VPNs with IPsec Configuration Guide.
4
But DMVPN definitely supports IKEv2, and Answer C says "...DMVPN does not". So the answer is probably D.
D 3
Selected Answer: D
DMVPN can be set up with IKEv2, so the answer is not C.
I couldn't find Cisco documentation to support this, but I found this configuration example: https://journey2theccie.wordpress.com/2020/03/13/ikev1-ikev2-configuration-in-dmvpn/
2
What is the difference between FlexVPN and DMVPN?
IPSec: One major difference between FlexVPN and default Dynamic Multipoint VPN (DMVPN) is the protocol used for negotiating IPsec Security Associations (SAs). While DMVPN defaults to using Internet Key Exchange version 1 (IKEv1), FlexVPN uses IKEv2.
C 2
Selected Answer: C
The answer is C
2
Tricky question, because DMVPN can do this by sharing the ipsec tunnel, so both can do it, but the most logical is D....Cisco style question.
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_dmvpn/configuration/15-mt/sec-conn-dmvpn-15-mt-book/sec-conn-dmvpn-share-ipsec-w-tun-protect.html#:~:text=Glossary%20Close-,Sharing%20IPsec%20with%20Tunnel%20Protection,results%20in%20network%20connectivity%20problems.&text=Security%20threats%20and%20the%20cryptographic,Encryption%20(NGE)%20white%20paper.
1
ANswer is C
1
I really like the comment on the following link for this discussion, per say- it looks like Answer is C
https://community.cisco.com/t5/network-security/what-is-the-difference-between-dmvpn-and-flexvpn/td-p/3438913
D 1
Selected Answer: D
Correct answer is D.
> DMVPN usually uses IKEv1 (though it can be configured for IKEv2 in some cases).