Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityMedium
A network engineer is configuring a FlexVPN solution on a Cisco ASR router. The design requires dynamic spoke-to-spoke tunnel establishment and support for multiple authentication methods. Which IKEv2 profile component is responsible for defining the authentication method used by the IKEv2 peers, such as pre-shared keys or digital certificates?
- AIKEv2 policy
- BIKEv2 proposal
- CIKEv2 profile
- DIKEv2 keyring
Show answer & explanationAnswer & explanation
Correct answer: D. IKEv2 keyring
The IKEv2 keyring is the specific component within the IKEv2 configuration that defines the authentication method to be used by the IKEv2 peers, such as pre-shared keys (PSK) or refers to a trustpoint for digital certificates. It stores the actual authentication credentials.
Why the other options are wrong
- A. An IKEv2 policy (or profile in some contexts) uses various components like proposals, keyrings, and local/remote addresses, but the keyring specifically defines the authentication credentials.
- B. An IKEv2 proposal defines the encryption, integrity, and Diffie-Hellman algorithms, not the authentication method itself.
- C. The IKEv2 profile is the overall container that ties together proposals, keyrings, and other settings, but the keyring is the specific element for authentication methods.
IKEv2 Keyring
A configuration component in Cisco's IKEv2 setup that defines the authentication credentials used by IKEv2 peers. It specifies either pre-shared keys or references to digital certificates (trustpoints) for peer authentication.
- Stores authentication information for IKEv2 peers.
- Can be configured with pre-shared keys for specific peers or a default.
- Can point to a trustpoint for certificate-based authentication.
Memory trick: Keyrings hold the keys to IKEv2 authentication!