hardMultiple ChoiceObjective-mapped
300-410 Practice Question: An MPLS network is experiencing label…
An MPLS network is experiencing label distribution failures. Router R1 (LSR) has the following configuration: mpls ldp neighbor 10.0.0.2 password cisco. Router R2 shows: 'show mpls ldp neighbor' lists R1 as 'Oper Down' with reason 'TCP MD5 authentication failure'. R1's 'show mpls ldp neighbor' shows R2 as 'Oper Down' with the same reason. Both routers have the same password configured. What is the root cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The LDP neighbor IP address configured on R1 does not match R2's LDP transport address, causing MD5 authentication to fail.
LDP uses TCP for session establishment, and MD5 authentication is configured via the 'mpls ldp neighbor' command. However, the password must match on both ends, and the command must specify the correct neighbor IP. If the IP address specified is incorrect (e.g., using a loopback IP instead of the transport address), the authentication will fail. Additionally, the 'mpls ldp password' command under the interface or global configuration may be required. In this scenario, the root cause is likely that the neighbor IP in the command does not match the actual LDP transport address (e.g., R1 uses 10.0.0.2 but R2's LDP transport address is 10.0.0.3).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The LDP neighbor IP address configured on R1 does not match R2's LDP transport address, causing MD5 authentication to fail.
Why this is correct
The 'mpls ldp neighbor' command expects the neighbor's LDP transport address (usually the router ID). If R1 uses 10.0.0.2 but R2's transport address is different (e.g., 10.0.0.3), the TCP connection uses a different IP, and MD5 authentication fails because the password is associated with the wrong IP.
- ✗
The password is not configured globally under 'mpls ldp password' on both routers.
Why it's wrong here
The 'mpls ldp neighbor' command with password is sufficient; global password is not required.
- ✗
The MPLS LDP session is using a different port number, causing authentication to be ignored.
Why it's wrong here
LDP uses TCP port 646; there is no alternative port.
- ✗
The interface between R1 and R2 has 'mpls ip' disabled.
Why it's wrong here
If mpls ip were disabled, LDP would not form at all, but the authentication failure indicates the session is attempted.
Go deeper
Related to this question
Learn chapter
Introduction to ENARSI Exam and Network Fundamentals
Key term
LDP Protocol
LDP, or Label Distribution Protocol, is a protocol that routers use to automatically exchange labels that enable MPLS (Multiprotocol Label Switching) to create fast, efficient paths for data packets across a network.
Key term
MPLS Label Distribution
MPLS Label Distribution is the process by which routers exchange labels that tell them how to forward packets across a network without looking at the IP address each time.
About these practice questions
This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.