Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures a site-to-site IPsec VPN…

An engineer configures a site-to-site IPsec VPN between two routers using OSPF as the routing protocol. The OSPF neighbor becomes stuck in EXSTART state. The engineer verifies that the IPsec tunnel is up and that both routers can ping each other's tunnel interfaces. What is the most likely cause of the OSPF adjacency issue?

⚠ Common exam trap

Cisco often tests the distinction between OSPF states—candidates confuse EXSTART (DBD exchange failure) with other states like INIT (hello mismatch) or 2-WAY (neighbor discovery), and overlook the impact of IPsec overhead on MTU and packet fragmentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The IPsec transform set uses ESP with authentication, adding 22 bytes of overhead, reducing the tunnel MTU to 1478 bytes, causing OSPF DBD packets larger than 1478 bytes to be dropped.

When OSPF neighbors are stuck in EXSTART state, it indicates a problem with Database Description (DBD) packet exchange. With an IPsec tunnel MTU of 1478 bytes (1500 minus 22 bytes for ESP authentication overhead), OSPF DBD packets that exceed this size are fragmented or dropped. Since IPsec does not support fragmentation of encrypted packets, the DBD exchange fails, preventing OSPF from progressing past EXSTART.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The OSPF network type on the tunnel interface is set to non-broadcast, preventing DBD exchange.

    Why it's wrong here

    Configuring the tunnel interface as non-broadcast forces OSPF to rely on manually configured neighbors, yet without the 'neighbor' command the routers never exchange Hello packets past the INIT state. The adjacency state machine must achieve 2-Way before DBD exchange; since non-broadcast prevents even Hello adjacency, the routers cannot reach EXSTART. Thus this misconfiguration blocks the entire database synchronization process rather than specifically stalling at DBD exchange, making it an incorrect cause.

  • ✓

    The IPsec transform set uses ESP with authentication, adding 22 bytes of overhead, reducing the tunnel MTU to 1478 bytes, causing OSPF DBD packets larger than 1478 bytes to be dropped.

    Why this is correct

    IPsec encapsulation adds overhead (e.g., 22 bytes for ESP-AES + SHA), reducing the effective MTU. OSPF DBD packets default to 1500 bytes on Ethernet, but if the tunnel MTU is lower, they are fragmented or dropped, leading to EXSTART state.

  • ✗

    The OSPF hello and dead intervals are mismatched between the two routers.

    Why it's wrong here

    OSPF validates Hello packets using the hello and dead interval fields; any mismatch causes the receiving router to silently drop the Hello, so the neighbor relationship remains in DOWN or INIT. The Dead interval is derived from the Hello interval, and if either differs, OSPF does not consider the neighbor valid and never transitions to 2-Way. Since EXSTART is reached only after the routers have passed the 2-Way and Master/Slave election, mismatched timers cannot produce the EXSTART state described in the scenario.

  • ✗

    The IPsec tunnel is using transport mode instead of tunnel mode, corrupting OSPF packets.

    Why it's wrong here

    Transport mode protects only the payload of the original IP packet and does not add an extra IP header, whereas tunnel mode encapsulates the entire original packet with a new IP header—but neither mode inherently corrupts OSPF packets. The real impact of transport mode is identical to tunnel mode: both add IPsec headers/trailers (e.g., ESP overhead) that reduce the effective MTU of the tunnel, which can trigger fragmentation or drops. Because the question specifically blames 'corrupting' packets and transport mode does not corrupt, this explanation fails to match the EXSTART symptom.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.