Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?

⚠ Common exam trap

The trap here is thinking that the crypto ACL should match the multicast or routing protocol directly, rather than the GRE encapsulation that carries them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The crypto ACL must permit GRE (protocol 47) traffic.

In a GRE over IPsec configuration, GRE encapsulates the multicast traffic, and then IPsec encrypts the GRE packets. The crypto ACL must match the GRE protocol (IP protocol 47) between the tunnel source and destination. This allows multicast and broadcast traffic to be carried over the tunnel because GRE handles the multicast encapsulation, and IPsec provides encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPsec must be configured in transport mode to preserve the original IP header.

    Why it's wrong here

    IPsec transport mode is used when the endpoints are the same as the traffic endpoints, such as in a host-to-host VPN. For GRE over IPsec, tunnel mode is used because the GRE endpoints (the routers) are different from the original traffic endpoints. Transport mode would not encapsulate the GRE packet properly.

  • ✗

    The tunnel interface must be configured with the tunnel mode gre multipoint command.

    Why it's wrong here

    The tunnel mode gre multipoint command is used for multipoint GRE (mGRE) tunnels, typically in DMVPN. For a simple point-to-point GRE over IPsec tunnel, the default tunnel mode gre is sufficient. Using mGRE would require additional NHRP configuration and is not necessary for this scenario.

  • ✓

    The crypto ACL must permit GRE (protocol 47) traffic.

    Why this is correct

    For GRE over IPsec, the crypto ACL defines which traffic is encrypted. Since GRE encapsulates the multicast traffic, the outer IP packet uses IP protocol 47. Therefore, the crypto ACL must permit GRE traffic between the tunnel endpoints. This ensures that all GRE-encapsulated packets, including multicast, are encrypted by IPsec.

  • ✗

    The crypto ACL must permit OSPF (protocol 89) traffic.

    Why it's wrong here

    If the crypto ACL permits OSPF directly, then only OSPF packets would be encrypted, but they would not be encapsulated in GRE. Without GRE encapsulation, multicast OSPF packets cannot be sent over an IPsec tunnel because IPsec does not support multicast. The correct approach is to permit GRE, which carries the OSPF packets.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.