hardMultiple Choice
300-410 Practice Question: An engineer configures IPsec between two routers…
An engineer configures IPsec between two routers using transform-set esp-aes 256 esp-sha-hmac. The tunnel fails to establish. Debug shows 'transform set proposal mismatch'. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the default behavior of 'esp-aes' (which defaults to 128-bit) versus explicit 'esp-aes 256', trapping candidates who assume that 'esp-aes' implies 256-bit or that the key length is negotiated automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The other router uses 'esp-aes' without specifying the key length, defaulting to 128-bit, causing a mismatch.
The debug output 'transform set proposal mismatch' indicates that the IPsec transform sets on the two peers do not match. When 'esp-aes 256' is configured on one router, the other router must explicitly specify 'esp-aes 256' as well; if it only uses 'esp-aes' without specifying a key length, Cisco IOS defaults to AES-128. This mismatch in encryption algorithm strength (256-bit vs. 128-bit) causes the IKE phase 2 negotiation to fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The other router uses 'esp-aes' without specifying the key length, defaulting to 128-bit, causing a mismatch.
Why this is correct
The transform-set keyword 'esp-aes' alone negotiates the default 128-bit AES key, whereas 'esp-aes 256' requires 256-bit. Since IPsec proposals must match exactly on encryption algorithm and key length, the differing AES strengths cause the proposal mismatch.
- ✗
The transform-set uses SHA-1, which is not supported by the other router.
Why it's wrong here
SHA-1 is supported by IPsec peers; esp-sha-hmac is the standard hash keyword and interoperates widely. The mismatch arises from differing encryption or hash proposals, not from SHA-1 being unsupported. It is tempting because SHA-1 is deprecated for other uses, but that does not cause this debug message.
- ✗
The IPsec proposal includes both esp-aes and esp-3des, causing confusion.
Why it's wrong here
A single transform-set cannot contain both esp-aes and esp-3des; the command syntax accepts one encryption algorithm, so this configuration is impossible. It is tempting because multiple proposals exist in IKE policy sets, but transform-set mismatch stems from differing single-algorithm definitions between peers.
- ✗
The transform-set is missing the authentication header.
Why it's wrong here
ESP provides confidentiality and integrity without AH; esp-sha-hmac supplies authentication, so AH is not required. The mismatch is caused by differing transform-set parameters, not a missing AH. It is tempting because AH offers integrity, but it is incompatible with NAT and unnecessary here.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.