Cisco CCNP Security Core (SCOR) 350-701Network SecurityMedium
A security engineer is designing a secure network for a new branch office. The design requires that all traffic between the branch office and the headquarters network traverse a secure, encrypted tunnel over the public internet. The solution must support both site-to-site connectivity and remote user access. Which VPN technology should be implemented to meet these requirements?
- ASSL VPN
- BDMVPN
- CGET VPN
- DIPsec VPN
Show answer & explanationAnswer & explanation
Correct answer: D. IPsec VPN
IPsec VPN is the most suitable technology for establishing secure, encrypted tunnels for both site-to-site and remote access connectivity over the public internet. It provides robust authentication, confidentiality, and integrity services, making it a standard for secure network communication.
Why the other options are wrong
- A. SSL VPNs are primarily designed for remote access for end-users and are less commonly used for dedicated site-to-site tunnels.
- B. DMVPN (Dynamic Multipoint VPN) is an IPsec-based solution optimized for spoke-to-spoke communication in hub-and-spoke topologies, but IPsec is the underlying technology that provides the core security.
- C. GET VPN (Group Encrypted Transport VPN) is used for 'any-to-any' encryption without IPsec tunnels between every pair of routers, typically for large-scale meshed networks, but it still relies on IPsec for encryption.
IPsec VPN
A suite of protocols used to secure IP communications by authenticating and encrypting each IP packet of a communication session.
- Provides confidentiality, integrity, authenticity
- Supports both tunnel and transport modes
- Widely used for site-to-site and remote access VPNs
Memory trick: IPsec is the backbone for secure tunnels.