A network administrator is deploying a site-to-site VPN using Cisco IOS GET VPN (Group Encrypted Transport VPN) on a service provider MPLS network. The administrator must ensure that the group members can communicate securely while maintaining any-to-any connectivity and minimizing tunnel overhead. Which two statements about GET VPN are true? (Choose two.)
The key server is a central component that manages group policies, generates and distributes keys, and authenticates group members. It uses the Group Domain of Interpretation (GDOI) protocol to securely send the GSA to members. Without a key server, group members cannot obtain the necessary keys to encrypt or decrypt traffic, making it a mandatory element in GET VPN deployments.
Why this answer
GET VPN uses a group security association managed by a key server, allowing any-to-any secure communication without per-peer tunnels. The key server distributes policies and keys via GDOI. This design preserves the original IP header for routing and supports both unicast and multicast, making it ideal for MPLS networks.
Exam trap
The trap here is assuming GET VPN uses point-to-point tunnels or encapsulates packets with a new IP header, when it actually uses a group SA and preserves the original header.