hardMultiple Choice
CCNP Practice Question: An engineer is configuring a FlexVPN…
An engineer is configuring a FlexVPN hub-and-spoke topology using IKEv2. The hub router is configured with a dynamic crypto map and a local pool for assigning IP addresses to spokes. The spokes are configured with a static crypto map and a tunnel interface with an IP address from the pool. The tunnel comes up, but the spoke cannot ping the hub's tunnel interface. The hub can ping the spoke's tunnel interface. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the misconception that a static IP on the spoke's tunnel interface is acceptable as long as the tunnel is up, but the key point is that the hub's route injection depends on the IP being within the configured pool.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The spoke is configured with a static IP address on the tunnel interface that is not in the hub's IP pool.
In a FlexVPN hub-and-spoke topology with IKEv2, the hub assigns IP addresses to spokes from a local pool. If the spoke's tunnel interface is configured with a static IP address that is not within the hub's pool, the hub will not recognize the spoke's tunnel IP as a valid address from its pool. This causes asymmetric routing: the hub can reach the spoke because it has a route to the static IP, but the spoke cannot reach the hub because the hub has no route back to the spoke's tunnel IP (or the hub's reverse route injection fails). The correct behavior is for the spoke to obtain its tunnel IP dynamically via IKEv2 configuration exchange or to use an IP from the hub's pool.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The spoke is configured with a static IP address on the tunnel interface that is not in the hub's IP pool.
Why this is correct
Correct. In FlexVPN, the hub assigns IP addresses from a pool. If the spoke statically configures an IP address, the hub may not have a route back to that address, causing asymmetric routing or unreachability.
- ✗
The hub is missing the 'tunnel protection ipsec' command on the tunnel interface.
Why it's wrong here
The command `tunnel protection ipsec` is what attaches an IPsec profile to the tunnel interface and is mandatory for negotiating IPsec SAs in FlexVPN. If it were missing on the hub, the tunnel could not encrypt traffic and the IKEv2 tunnel would never come fully operational. Since the tunnel is observed to be up, this command is necessarily present, making this option incorrect.
- ✗
The spoke's crypto map is not using the correct pre-shared key.
Why it's wrong here
In IKEv2, the pre-shared key is used during IKE SA authentication (the equivalent of Phase 1 in IKEv1). If the spoke's crypto map configured a different pre-shared key than the hub, the IKEv2 authentication exchange would fail, and no tunnel would ever be established. The fact that the tunnel is up proves the keys match, so a key mismatch is not the culprit.
- ✗
The hub's IKEv2 profile is not configured with 'authentication remote rsa-sig'.
Why it's wrong here
The `authentication remote rsa-sig` command in the hub's IKEv2 profile defines what authentication method the hub expects from the spoke. If this method did not match the spoke's configured authentication (e.g., if the spoke used a pre-shared key), the IKEv2 authentication would fail and the tunnel would not be up. Since the tunnel is active, the hub's authentication configuration must be consistent with the spoke's, so this cannot be the issue.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.