Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium

A network engineer is configuring a FlexVPN solution on a Cisco ASR router. The design requires dynamic spoke-to-spoke tunnel establishment and support for multiple authentication methods. Which IKEv2 profile component is responsible for defining the authentication method used by the IKEv2 peers, such as pre-shared keys or digital certificates?

  1. AIKEv2 policy
  2. BIKEv2 proposal
  3. CIKEv2 profile
  4. DIKEv2 keyring
Show answer & explanation

Correct answer: D. IKEv2 keyring

The IKEv2 keyring is the specific component within the IKEv2 configuration that defines the authentication method to be used by the IKEv2 peers, such as pre-shared keys (PSK) or refers to a trustpoint for digital certificates. It stores the actual authentication credentials.

Why the other options are wrong

  • A. An IKEv2 policy (or profile in some contexts) uses various components like proposals, keyrings, and local/remote addresses, but the keyring specifically defines the authentication credentials.
  • B. An IKEv2 proposal defines the encryption, integrity, and Diffie-Hellman algorithms, not the authentication method itself.
  • C. The IKEv2 profile is the overall container that ties together proposals, keyrings, and other settings, but the keyring is the specific element for authentication methods.

IKEv2 Keyring

A configuration component in Cisco's IKEv2 setup that defines the authentication credentials used by IKEv2 peers. It specifies either pre-shared keys or references to digital certificates (trustpoints) for peer authentication.

  • Stores authentication information for IKEv2 peers.
  • Can be configured with pre-shared keys for specific peers or a default.
  • Can point to a trustpoint for certificate-based authentication.

Memory trick: Keyrings hold the keys to IKEv2 authentication!

More Security questions