Courseiva
mediumMultiple Choice

300-410 Practice Question: Is troubleshooting an IPv6 connectivity issue…

A network engineer is troubleshooting an IPv6 connectivity issue between two sites connected via a 6to4 tunnel. The tunnel is configured on both routers and shows as up/up, but the engineer cannot ping the IPv6 address of the remote tunnel endpoint. The engineer checks the routing table and sees no route to the remote IPv6 prefix. What is the most likely cause of this problem?

⚠ Common exam trap

Cisco often tests the misconception that a 6to4 tunnel only requires the tunnel to be up/up, but the real issue is the routability of the derived 2002::/48 prefix when the source IPv4 address is private.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The tunnel source interface is configured with a private IPv4 address, causing the 6to4 prefix to be invalid.

For a 6to4 tunnel, the IPv6 address on the tunnel interface must be derived from the tunnel source's public IPv4 address using the 2002:IPv4-address::/48 prefix format. If the tunnel source interface has a private IPv4 address (e.g., 10.0.0.1), the resulting 6to4 prefix (2002:0a00:0001::/48) is non-routable over the public Internet because private addresses are not globally unique. This causes the remote router to have no route to the invalid prefix, breaking connectivity even though the tunnel interface is up/up.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The tunnel source interface is configured with a private IPv4 address, causing the 6to4 prefix to be invalid.

    Why this is correct

    A 6to4 tunnel forms its 2002::/16 IPv6 prefix from the router's IPv4 tunnel source. Private or RFC 1918 addresses like 10.0.0.1 or 192.168.1.1 cannot be embedded into a publicly valid 2002:V4ADDR::/16 prefix, so the router cannot derive or advertise a routable 6to4 prefix. This makes the source address the root cause of the tunnel failure, whereas other configuration aspects are irrelevant or secondary.

  • ✗

    The tunnel mode is incorrectly set to ipv6ip instead of 6to4.

    Why it's wrong here

    The 'tunnel mode ipv6ip' command configures a manually operated IPv6-over-IPv4 tunnel that requires explicit tunnel source and destination IPv4 addresses. A 6to4 tunnel, in contrast, uses automatic address mapping and has no tunnel destination; setting the wrong mode would cause different encapsulation behavior, but the tunnel interface would still come up administratively. Since the question reports a non-functional 6to4 tunnel, the invalid private source address, not the tunnel mode, is the critical fault.

  • ✗

    The tunnel destination is misconfigured with the remote router's IPv6 address instead of its IPv4 address.

    Why it's wrong here

    6to4 is fundamentally a point-to-multipoint mechanism; each router builds the outer IPv4 header based on the 2002::/16 prefix embedded in the destination IPv6 address. The 'tunnel destination' command is not used in 6to4 configuration and would be ignored or rejected by Cisco IOS, so any misconfiguration there cannot explain a down tunnel. The real issue is that the source interface's private IPv4 address produces an unusable 6to4 prefix.

  • ✗

    The IPv6 address on the tunnel interface is not in the 2002::/16 range.

    Why it's wrong here

    The IPv6 address assigned to the tunnel interface is a local, logical address and is not used to derive the 6to4 tunnel endpoints. 6to4 computes the next-hop and encapsulated IPv4 destination from the destination IPv6 packet's 2002:V4ADDR::/64 prefix, not from the interface's own address. Therefore, even if the tunnel interface holds an address in a different range, such as 2001:db8::1/64, it does not stop the tunnel from functioning; only a private source IPv4 address invalidates the prefix.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.