Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard
A network engineer is troubleshooting a FlexVPN spoke that fails to build a dynamic IPsec tunnel to the hub. The engineer verifies that IKEv2 is enabled, the crypto keyring is correctly configured with the hub's public key, and the IKEv2 profile points to the correct keyring. However, the tunnel still fails to establish. Upon inspection, it is found that the IKEv2 proposal does not match between the spoke and the hub. Which parameter within the IKEv2 proposal is crucial for agreeing on the encryption algorithm?
- AEncryption Algorithm
- BAuthentication Method
- CDiffie-Hellman Group
- DIntegrity Algorithm
Show answer & explanationAnswer & explanation
Correct answer: A. Encryption Algorithm
The Encryption Algorithm parameter within an IKEv2 proposal is crucial for agreeing on how the IKEv2 control plane traffic itself will be encrypted. A mismatch here will prevent the IKEv2 security association from forming, thus preventing the tunnel from building.
Why the other options are wrong
- B. Authentication Method is for peer authentication, not encryption algorithm.
- C. Diffie-Hellman Group is for key exchange, not encryption algorithm itself.
- D. Integrity Algorithm is for data integrity, not encryption.
IKEv2 Proposal Parameters
A set of cryptographic parameters proposed during IKEv2 negotiation, including encryption, integrity, PRF, and Diffie-Hellman group.
- Must match between peers for IKEv2 SA to form.
- Defines security for the IKEv2 control plane.
- Different from IPsec transform-set parameters (data plane).
Memory trick: An IKEv2 proposal is like a 'secret handshake' with specific steps and tools.