300-410 VPN Technologies Practice Question
A network administrator is troubleshooting an IPsec site-to-site VPN between two Cisco IOS routers. The tunnel is up, but traffic is not passing. The administrator suspects a routing issue. Which command should be used to verify that the crypto ACL matches the traffic being sent?
⚠ Common exam trap
The trap here is assuming that 'show crypto ipsec sa' alone can confirm ACL matches, but it only shows encrypted packets, not the ACL hit counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show access-lists
When an IPsec tunnel is up but traffic is not passing, a common cause is a mismatch between the crypto ACL and the actual traffic. The crypto ACL defines interesting traffic that should be encrypted. By using 'show access-lists', you can see if the ACL's permit entries are being hit by the traffic. If counters are not incrementing, the traffic is not matching the ACL, and you need to adjust it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
show access-lists
Why this is correct
'show access-lists' displays the configured ACLs and their hit counters. By examining the crypto ACL referenced in the crypto map, you can see if the counters are incrementing for the interesting traffic. If the counters are not incrementing, the ACL may not match the traffic, indicating a mismatch. This is a key step in troubleshooting IPsec VPNs when the tunnel is up but traffic is not flowing.
- ✗
show crypto ipsec sa
Why it's wrong here
'show crypto ipsec sa' displays the IPsec security associations, including the local and remote networks, encryption and authentication algorithms, and packet counters. While it can show if packets are being encrypted and decrypted, it does not directly show the crypto ACL configuration or whether it matches the traffic. It is useful for verifying that the SA is established and passing traffic, but not for checking ACL matches.
- ✗
show crypto isakmp sa
Why it's wrong here
'show crypto isakmp sa' displays the IKE security associations, including the peer, state, and authentication method. It is used to verify that Phase 1 (IKE) is established. However, it does not provide information about the crypto ACL or whether traffic is matching it. If the tunnel is up, IKE SA is likely fine, so this command is not the best for troubleshooting traffic selection issues.
- ✗
show crypto map
Why it's wrong here
'show crypto map' displays the crypto map configuration, including the peer, the ACL used, and the transform set. It shows which ACL is referenced, but it does not show whether that ACL matches the actual traffic being sent. To verify matching, you need to see the ACL itself and the traffic counters, which is done with 'show access-lists' or 'show crypto ipsec sa' for encrypted packets.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.