Courseiva
hardMultiple Choice

300-410 Practice Question: Is troubleshooting an IPv6 connectivity issue on…

A network engineer is troubleshooting an IPv6 connectivity issue on a router that is using a tunnel interface (IPv6 over IPv4). The engineer notices that traffic is not passing through the tunnel. The engineer checks the tunnel interface and finds an inbound IPv6 ACL that permits only certain IPv6 traffic. The engineer also sees that uRPF is enabled on the tunnel interface in strict mode. The tunnel source and destination are IPv4 addresses. The IPv6 traffic sourced from a network behind the tunnel is being dropped. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the interaction between uRPF and tunnel interfaces, where candidates mistakenly think the ACL is the issue or that uRPF only checks for the existence of a route, ignoring the strict mode requirement that the route must point back to the same interface the packet arrived on.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The uRPF strict mode check fails because the router does not have a route to the source IPv6 network pointing to the tunnel interface.

The uRPF strict mode check requires that the source IPv6 address of incoming traffic on the tunnel interface must have a route in the routing table pointing back to that same interface. Since the IPv6 traffic is sourced from a network behind the tunnel, the router likely has a route to that source network via a different interface (e.g., the physical LAN interface) or no route at all, causing uRPF to drop the packets. This is the most likely cause because the tunnel interface is the inbound interface for the decapsulated IPv6 packets, and uRPF strict mode validates the source address against the Forwarding Information Base (FIB) entry pointing to the tunnel interface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The uRPF strict mode check fails because the router does not have a route to the source IPv6 network pointing to the tunnel interface.

    Why this is correct

    In strict unicast RPF mode, the router verifies that the source address of a packet received on an interface is reachable via that same interface by consulting the FIB. Because the IPv6 source network's route points to a different interface (or is absent), the reverse-path lookup does not resolve to the tunnel interface, so the packet is discarded even though the tunnel itself is functional. The fix is to add a static route for that source network pointing to the tunnel interface, satisfying the strict asymmetry check.

  • ✗

    The ACL is blocking the IPv6 traffic because the tunnel interface does not support ACLs.

    Why it's wrong here

    The claim that tunnel interfaces cannot have ACLs is false; like physical interfaces, tunnel interfaces support both IPv4 and IPv6 ACLs, including the 'ipv6 traffic-filter' command shown. An ACL applied to a tunnel interface filters traffic that traverses the tunnel, but the problem here is not ACL filtering—it is a unicast RPF failure. Even if an ACL existed, its permit/deny logic would be evaluated independently from uRPF, and the absence of a matching deny entry shows ACLs are not the cause.

  • ✗

    The tunnel is not configured with the correct IPv4 source and destination.

    Why it's wrong here

    If the tunnel's IPv4 source or destination were incorrect, the tunnel interface would not reach the up/up state and no IPv6 traffic would be received over it. The scenario indicates that packets are arriving on the tunnel, which proves the underlay transport is correctly configured and reachable. Therefore, the uRPF drop is unrelated to the tunnel's IPv4 encapsulation parameters, and changing them would have no effect on the strict-mode source validation failure.

  • ✗

    The uRPF mode should be loose mode to allow traffic from any source.

    Why it's wrong here

    Incorrect because loose mode would still require a route to the source, but the issue is the route pointing to the tunnel interface; loose mode might work if there is any route, but the scenario implies strict mode is the problem.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.