300-410 VPN Technologies Practice Question
A network engineer is configuring a GRE over IPsec tunnel between two Cisco routers. The engineer wants to ensure that multicast traffic, such as OSPF hello packets, is encrypted and sent over the tunnel. Which statement about the configuration is true?
⚠ Common exam trap
The trap here is thinking that the crypto ACL should match the multicast or routing protocol directly, rather than the GRE encapsulation that carries them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The crypto ACL must permit GRE (protocol 47) traffic.
In a GRE over IPsec configuration, GRE encapsulates the multicast traffic, and then IPsec encrypts the GRE packets. The crypto ACL must match the GRE protocol (IP protocol 47) between the tunnel source and destination. This allows multicast and broadcast traffic to be carried over the tunnel because GRE handles the multicast encapsulation, and IPsec provides encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPsec must be configured in transport mode to preserve the original IP header.
Why it's wrong here
IPsec transport mode is used when the endpoints are the same as the traffic endpoints, such as in a host-to-host VPN. For GRE over IPsec, tunnel mode is used because the GRE endpoints (the routers) are different from the original traffic endpoints. Transport mode would not encapsulate the GRE packet properly.
- ✗
The tunnel interface must be configured with the tunnel mode gre multipoint command.
Why it's wrong here
The tunnel mode gre multipoint command is used for multipoint GRE (mGRE) tunnels, typically in DMVPN. For a simple point-to-point GRE over IPsec tunnel, the default tunnel mode gre is sufficient. Using mGRE would require additional NHRP configuration and is not necessary for this scenario.
- ✓
The crypto ACL must permit GRE (protocol 47) traffic.
Why this is correct
For GRE over IPsec, the crypto ACL defines which traffic is encrypted. Since GRE encapsulates the multicast traffic, the outer IP packet uses IP protocol 47. Therefore, the crypto ACL must permit GRE traffic between the tunnel endpoints. This ensures that all GRE-encapsulated packets, including multicast, are encrypted by IPsec.
- ✗
The crypto ACL must permit OSPF (protocol 89) traffic.
Why it's wrong here
If the crypto ACL permits OSPF directly, then only OSPF packets would be encrypted, but they would not be encapsulated in GRE. Without GRE encapsulation, multicast OSPF packets cannot be sent over an IPsec tunnel because IPsec does not support multicast. The correct approach is to permit GRE, which carries the OSPF packets.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.