🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)51 / 128
Question 51 of 128

An engineer configured a route-based IPsec VTI tunnel from an on-premises Cisco IOS XE router to an AWS VPN gateway. IKEv2 Phase 1 completes successfully and the SA is established, but no Phase 2 IPsec SA forms and 'show crypto ipsec sa' shows zero encrypted/decrypted packets. Debug output on the router shows 'ts_unacceptable' notifications received from AWS. What is the most likely cause?

Reviewed for accuracy · Report an issueNext question