Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: R1 and R2 are connected via an IPsec VPN tunnel

R1 and R2 are connected via an IPsec VPN tunnel. They are running OSPF over the tunnel. R1's show ip ospf neighbor shows R2 as FULL, but R1's show ip ospf database shows the LSA from R2 but with a high age (e.g., 3600). R1's show ip route does not have routes from R2. What is the root cause?

⚠ Common exam trap

Cisco often tests the distinction between neighbor state (which can appear FULL momentarily after a flap) and LSA age (which reflects the last successful refresh), leading candidates to overlook that a short dead interval can cause LSA expiration without a permanent neighbor down state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The OSPF dead interval on R1's tunnel interface is too short, causing frequent neighbor resets and LSA aging.

When the OSPF dead interval on R1's tunnel interface is too short, R1 may temporarily lose neighbor adjacency with R2, causing the LSA from R2 to be prematurely aged out (age reaches 3600, the MaxAge) and removed from the OSPF database. Even though the neighbor state shows FULL at the moment of inspection, the LSA has already been flushed due to a previous timeout, so routes are not installed in the routing table.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The OSPF dead interval on R1's tunnel interface is too short, causing frequent neighbor resets and LSA aging.

    Why this is correct

    A short dead interval causes the neighbor to be declared dead and re-established, but LSAs are not refreshed, leading to high age and eventual removal.

  • The IPsec tunnel is dropping OSPF packets due to MTU issues.

    Why it's wrong here

    MTU issues would cause packet loss, not LSA aging without neighbor flapping.

  • OSPF network type is point-to-multipoint, causing LSA flooding issues.

    Why it's wrong here

    Point-to-multipoint works fine with IPsec tunnels.

  • R2 has a distribute-list out filtering OSPF routes.

    Why it's wrong here

    A distribute-list would prevent LSA generation, but the LSA is present in the database.

Visual reference

R1 R2 R3 R4 10 100 10 100 OSPF picks R1→R2→R4 (cost 20) over R1→R3→R4 (cost 200)

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.