Courseiva
VPN Technologies →mediumMultiple Choice

300-410 VPN Technologies Practice Question

A network engineer is configuring a GRE tunnel over an IPsec VPN to support multicast traffic between two sites. The engineer notices that multicast traffic is not passing through the tunnel, although unicast traffic works. Which of the following is the most likely reason?

⚠ Common exam trap

The trap here is assuming that IPsec or the ACL is blocking multicast, when the real issue is the lack of multicast routing configuration on the tunnel and physical interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Multicast routing is not enabled on the tunnel interfaces or the physical interfaces.

Multicast traffic over a GRE tunnel requires multicast routing to be enabled on both the tunnel interface and the physical interface. Additionally, a multicast routing protocol like PIM must be configured. Without these, the router will not forward multicast packets, even though unicast traffic works. The IPsec ACL typically permits GRE, so it does not need to match multicast directly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The IPsec transform set does not support multicast traffic.

    Why it's wrong here

    IPsec can encrypt multicast traffic if it is encapsulated in GRE. The transform set defines encryption and hashing algorithms, not traffic types. The issue is not the transform set but the configuration of multicast routing over the tunnel. IPsec itself does not inherently block multicast; it encrypts whatever is sent through the tunnel.

  • ✗

    The IPsec ACL is not permitting multicast traffic.

    Why it's wrong here

    The IPsec ACL defines interesting traffic for encryption. In a GRE over IPsec scenario, the ACL typically matches GRE (protocol 47) between the tunnel endpoints, not the multicast traffic itself. The multicast traffic is encapsulated in GRE, so the ACL only needs to permit GRE. Thus, an ACL that does not explicitly permit multicast is not the cause.

  • ✗

    The GRE tunnel interface is not configured with a tunnel source and destination.

    Why it's wrong here

    If the tunnel source and destination were missing, the tunnel would not come up at all, and even unicast would fail. Since unicast works, the tunnel is operational. The problem is specific to multicast, indicating a multicast routing configuration issue rather than basic tunnel parameters.

  • ✓

    Multicast routing is not enabled on the tunnel interfaces or the physical interfaces.

    Why this is correct

    For multicast traffic to traverse a GRE tunnel, multicast routing must be enabled on the tunnel interface and the physical interface carrying the tunnel. Additionally, an appropriate multicast routing protocol (e.g., PIM) must be configured. Without enabling multicast routing, the router will not forward multicast packets into or out of the tunnel, even though unicast works. This is the most likely cause.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.