hardMultiple Choice
300-410 Practice Question: An engineer configures unicast Reverse Path…
An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on the outside interface of a router that terminates an IPsec site-to-site VPN. After the configuration, the VPN tunnel establishes, but traffic from the remote site is not forwarded correctly. The engineer verifies that the IPsec tunnel is up and that the routing table has the correct routes. What is the most likely explanation?
⚠ Common exam trap
Cisco often tests the subtle interaction between uRPF strict mode and IPsec VPNs, where candidates mistakenly think the tunnel mode or encryption causes the issue, rather than the interface-specific reverse path check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The return route for the remote site's physical IP points to the tunnel interface, but the packet arrives on the physical interface, so uRPF drops it because the source IP is not reachable via the incoming interface.
In strict mode, uRPF checks that the source IP address of an incoming packet is reachable via the exact interface on which the packet arrived. For IPsec site-to-site VPN traffic, the encapsulated (original) packet arrives on the physical outside interface, but the routing table's return route for the remote site's physical IP (the tunnel endpoint) points to the tunnel interface (e.g., a virtual tunnel interface or crypto map). Because the source IP is not reachable via the physical incoming interface, uRPF drops the packet, even though the IPsec tunnel is up and the routes are correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IPsec tunnel uses transport mode, which does not encapsulate the original source IP, causing uRPF to see the remote router's physical IP as the source.
Why it's wrong here
Transport mode does not add a new outer IP header; it inserts the ESP or AH header after the original IP header, leaving the source IP unchanged. Thus, uRPF does indeed see the remote router's physical IP as the source, but that fact alone does not cause the drop. The real reason is that the routing table's reverse path for that source IP points to the tunnel interface, not to the physical interface on which the decrypted packet arrived, so strict RPF rejects the packet.
- ✓
The return route for the remote site's physical IP points to the tunnel interface, but the packet arrives on the physical interface, so uRPF drops it because the source IP is not reachable via the incoming interface.
Why this is correct
The correct issue is a reverse-path forwarding mismatch on the physical interface. After decryption, the inner packet's source is the remote site's physical IP, and it arrives on the physical interface, such as GigabitEthernet0/0. Strict unicast RPF verifies that the route back to that source traverses the same physical interface; if the best route to the remote router's physical IP is via the tunnel interface, the source is considered asymmetric, and the packet is dropped. Thus, uRPF rejects the packet because the incoming interface is not the interface used to reach the source IP.
- ✗
The uRPF configuration includes the 'allow-default' option, which allows packets with a default route, but the remote site's IP is not in the default route.
Why it's wrong here
The 'allow-default' option on Cisco uRPF is intended for scenarios where a default route is the only route toward the source IP; it permits those packets so that uRPF does not drop them. In this scenario, the route to the remote site's physical IP is a specific route via the tunnel interface, not a default route. Therefore, enabling 'allow-default' would have no effect: the packet is dropped because the reverse path is a tunnel route, not because of any default-route behavior. This answer incorrectly assumes that the remote IP's lack of a default route is the trigger, when the actual problem is a specific tunnel route.
- ✗
The IPsec transform set uses ESP with authentication, which changes the source IP of the packet.
Why it's wrong here
ESP with authentication, such as esp-sha-hmac, appends an authentication trailer to the packet and, in transport mode, does not modify the original IP header. The source IP address in the decrypted packet remains the remote router's physical IP; IPsec does not manipulate addressing for uRPF purposes. Thus, this option misidentifies the mechanism: uRPF sees the same source IP whether ESP includes authentication or not, and the drop is caused by the reverse route pointing to the tunnel, not by any IPsec authentication altering the source.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.