300-410 VPN Technologies Practice Question
A network administrator is troubleshooting a site-to-site IPsec VPN between two Cisco IOS routers. IKEv1 Phase 1 completes and the peer is authenticated, but the administrator sees that no IPsec SA is installed and interesting traffic is dropped. The administrator confirms the transform sets, ACLs, and pre-shared keys match on both sides. Which configuration element should the administrator verify next on both routers?
⚠ Common exam trap
The trap here is focusing on Phase 1 settings such as lifetime or identity, when a completed Phase 1 with no SA points squarely at mismatched Phase 2 proposal parameters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Phase 2 proposal parameters, including encryption, hash, and PFS group
When IKE Phase 1 succeeds but no IPsec SA appears, the failure is almost always in the Phase 2 exchange. Both peers must agree on identical IPsec proposal parameters: encryption, integrity or hash, and the PFS Diffie-Hellman group if enabled. A single mismatch in any of these causes the responder to reject quick mode, leaving Phase 1 up while interesting traffic is dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The crypto map sequence numbers and the ACL referenced by each map
Why it's wrong here
The administrator already confirmed the ACLs match, and mismatched crypto map sequence numbers would typically cause traffic to hit a different map entry rather than prevent Phase 2 from completing entirely. While the map binds the ACL, transform set, and peer, the stated symptom of a completed Phase 1 with no SA points to the proposal matching rather than the map ordering, so this is not the most likely remaining cause.
- ✗
The IKEv1 Phase 1 lifetime values on each peer
Why it's wrong here
A Phase 1 lifetime mismatch does not stop the initial IKE SA from forming; the lower value simply causes renegotiation sooner. Since the administrator reports Phase 1 completes and the peer authenticates, the lifetime is not the cause of the missing Phase 2 SA. Lifetime values affect how long the IKE SA persists, not whether quick mode succeeds, so this does not explain the dropped interesting traffic.
- ✗
The routing table entries for the remote protected subnet
Why it's wrong here
A missing route to the remote subnet would prevent the router from forwarding the encrypted packet, but it would not stop the IPsec SA from being negotiated and installed. The symptom here is that no SA exists at all, which is a negotiation failure rather than a forwarding failure. Routing issues would appear after the SA is up, so this is not the element to verify for the stated problem.
- ✓
The Phase 2 proposal parameters, including encryption, hash, and PFS group
Why this is correct
Phase 2 requires both peers to agree on a matching IPsec proposal: encryption algorithm, hash or integrity algorithm, and, if perfect forward secrecy is configured, the Diffie-Hellman group. If any of these differ, the responder rejects the quick mode exchange and no IPsec SA is created even though Phase 1 is up. Verifying the proposal on both routers is the correct next step for this symptom.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.