mediumMultiple ChoiceObjective-mapped
300-410 Practice Question: Is troubleshooting an IPsec site-to-site VPN that…
A network engineer is troubleshooting an IPsec site-to-site VPN that uses a GRE tunnel. The GRE tunnel is up/up, and EIGRP is forming an adjacency over it. However, traffic from the local LAN to the remote LAN is not working. The engineer pings the remote LAN IP from the local router and it succeeds. What is the most likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The local router does not have a route to the remote LAN subnet in its routing table.
The GRE tunnel and routing protocol are working, but traffic from the LAN is failing. This indicates that the routing table on the local router does not have a route to the remote LAN subnet, or the route points to the wrong next-hop. The ping from the router succeeds because the router uses its own IP as source, which is directly connected to the tunnel.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The local router does not have a route to the remote LAN subnet in its routing table.
Why this is correct
Correct because the router can ping the remote LAN using its own IP, but if there is no route for the remote LAN subnet, traffic from LAN hosts will be dropped.
- ✗
The crypto map access list does not include the local LAN subnet.
Why it's wrong here
Incorrect because the tunnel is up and EIGRP is working, so the access list is likely correct for the tunnel traffic.
- ✗
The GRE tunnel keepalive is disabled.
Why it's wrong here
Incorrect because keepalive only affects tunnel stability, not routing.
- ✗
The IPsec transform set is missing authentication.
Why it's wrong here
Incorrect because the tunnel is up and working for router-initiated traffic, so the transform set is fine.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.