🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)66 / 128
Question 66 of 128

A network engineer establishes a route-based IPsec VPN using a Virtual Tunnel Interface (VTI) from an on-premises Cisco IOS XE router to a Google Cloud HA VPN gateway. BGP is configured across the tunnel to exchange routes with the GCP Cloud Router (ASN 65001; on-prem ASN 65500). After the IKEv2 SA and tunnel come up, the interface shows 'up/up', but the BGP session repeatedly cycles between Idle and Active and never reaches Established. Manual pings to the Cloud Router's BGP peer IP succeed. What is the MOST likely cause?

Reviewed for accuracy · Report an issueNext question