hardMultiple Choice
300-410 Practice Question: An engineer configures an IPsec site-to-site VPN
An engineer configures an IPsec site-to-site VPN. The tunnel comes up, but no traffic passes. The engineer checks the crypto map and access-lists. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the misconception that a crypto map applied to an interface automatically encrypts all traffic, when in reality the access-list must explicitly permit the traffic to be encrypted, and a missing permit causes the tunnel to appear up but pass no traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The access-list defining interesting traffic is missing the 'permit' statement for the actual traffic flow.
The access-list defining interesting traffic for the crypto map must explicitly include a 'permit' statement for the traffic that should be encrypted. Without this permit, the router will not classify the traffic as interesting, so IPsec will not attempt to encrypt it, and the traffic will be dropped or sent in clear depending on the crypto map configuration. The tunnel can still come up because IKE and IPsec SA negotiation is triggered by interesting traffic, but if the access-list is missing the permit, no traffic triggers the SA establishment, and existing SAs may remain idle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The crypto map is applied to the wrong interface, causing the traffic to bypass encryption.
Why it's wrong here
Applying the crypto map to the wrong interface would prevent that interface from establishing an IPsec SA for its traffic, because the crypto map's transform set and ACL are never matched on the egress interface. Since the problem statement confirms the tunnel is up, the crypto map must be on the correct interface, so this cannot be the cause of the bypass.
- ✓
The access-list defining interesting traffic is missing the 'permit' statement for the actual traffic flow.
Why this is correct
An IPsec crypto map uses an extended access-list to define interesting traffic; only packets explicitly permitted by that ACL are protected by the tunnel. If the actual source/destination flow lacks a permit statement, the router forwards it in clear text (or drops it if crypto map drop-on-fail is set) even while the tunnel remains up for other traffic. This exactly matches the symptom of traffic bypassing encryption despite an active tunnel.
- ✗
The IPsec transform set uses ESP with no encryption, so traffic is sent in clear.
Why it's wrong here
A transform set configured with ESP-NULL (esp-null) still provides authentication and anti-replay but performs no payload encryption, so traffic would be encapsulated in ESP yet remain readable in a packet capture. This would be a confidentiality failure, not a bypass of encapsulation — the packets would still be tunneled through the crypto map. Since the issue is that traffic is unencrypted and presumably not even tunneled, this option does not explain the behavior.
- ✗
The IKE phase 1 policy uses aggressive mode, which is incompatible with the crypto map.
Why it's wrong here
Aggressive mode is an IKE phase 1 attribute that determines how ISAKMP SAs are negotiated, using fewer exchanges and no preshared-key protection; it is compatible with crypto maps and does not influence which traffic is encrypted. The crypto map's access-list alone decides interesting traffic in phase 2. Because the tunnel is up, IKE completed successfully, so aggressive mode (or main mode) has no bearing on the clear-text flow.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.