IPsec Cloud Connectivity
Drill 20 practice questions focused entirely on IPsec Cloud Connectivity for the Cisco 300-440 exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
A network engineer is connecting an on-premises Cisco IOS XE router to a native AWS Site-to-Site VPN using two IPsec tunnels terminated on an AWS Virtual Private Gateway. During configuration, the engineer must specify the transform set and IPsec mode required for the tunnel to establish successfully with the AWS native endpoint (which does not support GRE encapsulation). Which IPsec configuration element must be used on the IOS XE Virtual Tunnel Interface (VTI) to match the AWS native VPN endpoint?
A network engineer configures a GRE over IPsec tunnel between an on-premises Cisco IOS XE router and an AWS-hosted Cisco IOS XE router across the public internet. BGP peers establish over the tunnel and small ping tests succeed, but users report that large file transfers and HTTPS sessions to cloud applications stall or fail intermittently. The physical WAN interface uses the standard 1500-byte MTU. What is the most effective configuration change on the tunnel interface to resolve this issue?
A network engineer is establishing a site-to-site VPN from an on-premises Cisco IOS XE router to a native AWS Virtual Private Gateway (VGW). AWS has generated a configuration file specifying two tunnels, each with a pre-shared key and an inside tunnel address in the 169.254.0.0/16 range. The engineer wants dynamic route exchange over the tunnels using BGP. When configuring the IOS XE tunnel interfaces to match the AWS native endpoint, which combination correctly reflects how the tunnel must be built?
A network engineer is configuring a route-based IPsec (VTI) tunnel from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (route-based, Generation 2). The IKEv2 SA is failing to establish, and debugs on the IOS XE router show the negotiation stalling during the IKE_SA_INIT exchange. The engineer confirms that the pre-shared key, IKEv2 encryption, and integrity algorithms are all correctly matched to Azure's default IPsec/IKE policy. Which additional IKEv2 proposal parameter must the engineer verify matches the Azure default policy to allow IKE_SA_INIT to complete?
You are configuring a route-based IPsec VPN from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (VpnGw2, Generation2). Azure will terminate the tunnel using IKEv2. To ensure Phase 2 (IPsec SA / child SA) negotiation succeeds with Azure's default supported parameters while maximizing hardware-accelerated throughput, which IPsec transform set should you configure on the IOS XE router?
A network engineer is building a GRE-over-IPsec tunnel from an on-premises Cisco IOS XE router to an Azure native VPN Gateway. Because the Azure VPN Gateway does not support GRE encapsulation, the engineer must terminate the design using a supported model while still reaching the 10.50.0.0/16 Azure VNet address space. The on-premises router uses a route-based configuration with a virtual tunnel interface (Tunnel1) and no dynamic routing protocol is permitted by policy. Which action correctly establishes reachability to the Azure VNet over this tunnel?
A network engineer is designing GRE-over-IPsec connectivity from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (not a cloud-hosted IOS XE instance). The design requires a routed tunnel interface running BGP over the encrypted overlay. During testing, IKEv2 and IPsec SAs come up successfully, but the GRE tunnel interface never reaches the up/up state and no BGP session forms. What is the most likely root cause of this failure?
A network engineer is building a GRE over IPsec tunnel from an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in AWS. Both sides use IKEv2 with pre-shared key authentication. The IKEv2 SA comes up intermittently and the logs on the on-premises router show 'IKEv2 profile not found' during some negotiations, even though a single IKEv2 profile is configured. The peer sits behind a NAT device, so the source address seen for its IKE negotiations does not match the address configured in the profile. What is the most likely configuration cause and the correct fix?
An engineer is establishing an IPsec tunnel from an on-premises Cisco IOS XE router to a cloud-hosted Cisco IOS XE router in AWS. The on-premises router sits behind a corporate firewall that performs PAT (NAT overload) for all outbound traffic. IKEv2 Phase 1 negotiation begins but the tunnel never fully establishes, and debugs show the peers detecting an address translation during negotiation. Which behavior must occur for the IPsec tunnel to establish successfully through the PAT device?
A network engineer is configuring a GRE over IPsec tunnel from an on-premises Cisco IOS XE router to a Google Cloud HA VPN gateway that terminates a native (non-Cisco) endpoint. The engineer wants to protect the GRE tunnel with IPsec and dynamically exchange routes over the overlay. When reviewing the design, the team lead notes that the chosen Google Cloud HA VPN gateway does not support GRE encapsulation at all. What is the correct action to establish encrypted, routed connectivity to this native Google Cloud endpoint?
A network engineer is building a GRE-over-IPsec design from an on-premises Cisco IOS XE router to a native Google Cloud HA VPN gateway. The requirement is that the connection provide a 99.99% availability SLA from Google. During design review, a colleague proposes terminating a single IPsec tunnel from the IOS XE router to one HA VPN gateway interface. What must the engineer do instead to meet the SLA requirement?
A network engineer is designing GRE over IPsec connectivity from an on-premises Cisco IOS XE router to a native Google Cloud HA VPN gateway. The engineer initially proposed running a GRE tunnel encapsulated in IPsec directly to the Cloud VPN gateway endpoint. During validation, the tunnel to the native Cloud VPN gateway will not establish the GRE overlay. What is the correct explanation and remediation for connecting to the native Google Cloud VPN endpoint?
A network engineer is building a GRE over IPsec tunnel from an on-premises Cisco IOS XE router to a cloud-hosted Cisco IOS XE router in AWS to run eBGP across the overlay. After configuring the IPsec profile, tunnel interface, and BGP peering over the tunnel IP addresses, the IPsec SA comes up and the BGP session reaches Established, but it repeatedly resets once the peers exchange their full routing tables, and large file transfers across the tunnel stall. The tunnel source is a public interface behind a 1500-byte MTU internet path. What is the MOST likely cause and the correct remediation?
A network engineer is configuring a route-based IPsec VPN from an on-premises Cisco IOS XE router to a native Azure VPN Gateway over the internet. The design requires that traffic selectors be defined by the routing table rather than by policy-based ACLs, so that additional Azure VNets can be reached later simply by adding routes. Which IOS XE configuration approach meets this requirement?
An engineer connects an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in Azure over an IPsec VPN using a route-based (VTI) tunnel. The on-premises site runs OSPF internally, while eBGP is used across the IPsec tunnel to the cloud router to exchange prefixes. The engineer redistributes BGP-learned cloud prefixes into the on-premises OSPF process. After the change, internal OSPF routers receive the cloud prefixes but users report that traffic to the cloud is intermittently blackholed when a second, less-preferred WAN path also injects the same prefixes. What is the most effective way to ensure the OSPF-redistributed cloud routes are correctly and consistently preferred?
A network engineer connects an on-premises Cisco IOS XE router to Google Cloud using two HA VPN tunnels, each terminating on a separate Cloud Router BGP interface in the same region. The on-premises router establishes eBGP sessions over both tunnels and receives identical prefixes from Google Cloud with the same AS-path length and MED. The engineer wants outbound traffic from on-premises to actively use both tunnels simultaneously for the cloud-bound prefixes. What must be configured on the Cisco IOS XE router to achieve this?
An engineer connects an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in an AWS VPC using two parallel IPsec VTI tunnels for redundancy. Both tunnels run eBGP over the tunnel interfaces to the same remote AS. The engineer notices that only one tunnel carries traffic, even though both BGP sessions are established and advertising the same prefixes. Return traffic from AWS also uses only a single tunnel. The engineer wants both tunnels to actively share load for the cloud-destined prefixes. Which configuration change on the IOS XE routers achieves this?
A network engineer has built two IPsec VTI tunnels from an on-premises Cisco IOS XE router to a Cisco IOS XE router hosted in an AWS VPC. Both tunnels run eBGP and advertise the same on-premises prefixes. The engineer wants all traffic sourced from the cloud-hosted router destined to on-premises to prefer Tunnel1, using Tunnel2 only if Tunnel1 fails. Which BGP attribute should be configured, and on which router, to achieve this deterministic outbound path selection from the cloud router?
A network engineer has established a redundant IPsec VTI connection between an on-premises Cisco IOS XE router and a Cisco IOS XE router hosted in AWS. The on-premises router advertises 40 individual /24 prefixes over BGP toward the AWS-hosted router. The cloud team reports that the AWS-hosted router is receiving all 40 routes, but they want the on-premises router to advertise only a single aggregate prefix (10.10.0.0/18) while suppressing the more-specific /24 routes to reduce the BGP table size. Which configuration on the on-premises router achieves this?
An engineer builds a route-based IPsec VTI tunnel between an on-premises Cisco IOS XE router and an AWS cloud-hosted Cisco IOS XE router across the internet. The tunnel establishes successfully and passes traffic, but every few hours users report a brief drop of about 20-30 seconds, after which connectivity restores by itself. Debugs on the on-premises router show IKEv2 CHILD_SA re-creation events coinciding with the outages, and the two routers are configured with different IPsec SA lifetimes (on-prem 3600 seconds, AWS side 28800 seconds). What is the MOST likely cause of the periodic outage, and what corrective action addresses it?
More 300-440 practice
Keep going with the other Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440) domains, or take a full timed mock exam.
← Back to 300-440 overview