What this objective tests
300-410 VPN Technologies — Key Topics
Be able to configure and verify IPsec, DMVPN, FlexVPN, and GET VPN on Cisco routers, and to isolate whether a tunnel failure is Phase 1 or Phase 2. The most important thing: confirm both peers agree on every IKE and IPsec parameter, including identity and proxy ACLs.
- IKEv1/IKEv2 Phase 1 and Phase 2 parameter matching: encryption, hashing, DH group, lifetime, and pre-shared key or certificate authentication
- IPsec crypto map, IPsec profile, and transform set configuration, including ACL or VTI-based interesting traffic selection
- DMVPN Phase 1/2/3 with NHRP, mGRE, and tunnel protection, plus FlexVPN hub-and-spoke IKEv2 authorization
- GET VPN group member and key server roles, including key distribution and the GDOI protocol