Courseiva
hardMultiple Choice

CCNP Practice Question: An engineer is configuring a FlexVPN…

An engineer is configuring a FlexVPN hub-and-spoke topology using IKEv2. The hub router is configured with a dynamic crypto map and a local pool for assigning IP addresses to spokes. The spokes are configured with a static crypto map and a tunnel interface with an IP address from the pool. The tunnel comes up, but the spoke cannot ping the hub's tunnel interface. The hub can ping the spoke's tunnel interface. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that a static IP on the spoke's tunnel interface is acceptable as long as the tunnel is up, but the key point is that the hub's route injection depends on the IP being within the configured pool.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The spoke is configured with a static IP address on the tunnel interface that is not in the hub's IP pool.

In a FlexVPN hub-and-spoke topology with IKEv2, the hub assigns IP addresses to spokes from a local pool. If the spoke's tunnel interface is configured with a static IP address that is not within the hub's pool, the hub will not recognize the spoke's tunnel IP as a valid address from its pool. This causes asymmetric routing: the hub can reach the spoke because it has a route to the static IP, but the spoke cannot reach the hub because the hub has no route back to the spoke's tunnel IP (or the hub's reverse route injection fails). The correct behavior is for the spoke to obtain its tunnel IP dynamically via IKEv2 configuration exchange or to use an IP from the hub's pool.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The spoke is configured with a static IP address on the tunnel interface that is not in the hub's IP pool.

    Why this is correct

    Correct. In FlexVPN, the hub assigns IP addresses from a pool. If the spoke statically configures an IP address, the hub may not have a route back to that address, causing asymmetric routing or unreachability.

  • ✗

    The hub is missing the 'tunnel protection ipsec' command on the tunnel interface.

    Why it's wrong here

    The command `tunnel protection ipsec` is what attaches an IPsec profile to the tunnel interface and is mandatory for negotiating IPsec SAs in FlexVPN. If it were missing on the hub, the tunnel could not encrypt traffic and the IKEv2 tunnel would never come fully operational. Since the tunnel is observed to be up, this command is necessarily present, making this option incorrect.

  • ✗

    The spoke's crypto map is not using the correct pre-shared key.

    Why it's wrong here

    In IKEv2, the pre-shared key is used during IKE SA authentication (the equivalent of Phase 1 in IKEv1). If the spoke's crypto map configured a different pre-shared key than the hub, the IKEv2 authentication exchange would fail, and no tunnel would ever be established. The fact that the tunnel is up proves the keys match, so a key mismatch is not the culprit.

  • ✗

    The hub's IKEv2 profile is not configured with 'authentication remote rsa-sig'.

    Why it's wrong here

    The `authentication remote rsa-sig` command in the hub's IKEv2 profile defines what authentication method the hub expects from the spoke. If this method did not match the spoke's configured authentication (e.g., if the spoke used a pre-shared key), the IKEv2 authentication would fail and the tunnel would not be up. Since the tunnel is active, the hub's authentication configuration must be consistent with the spoke's, so this cannot be the issue.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.