A spoke has two Internet connections for failover.How can you achieve optimum failover
without affecting any other router in the DMVPN cloud?
A.
Create another DMVPN cloud by configuring another tunnel interface that is sourced from
the second ISP link.
B.
Use another router at the spoke site, because two ISP connections on the same router for
the same hub is not allowed.
C.
Configure SLA tracking, and when the primary interface goes down, manually change the
tunnel source of the tunnel interface.
D.
Create another tunnel interface with same configuration except the tunnel source, and
configure the if-state nhrp and backup interface commands on the primary tunnel interface.
I believe is “D”
The answer is “D”.
Interface State Control
The Interface State Control feature allows NHRP to control the state of the interface based on whether the tunnels on the interface are live. If NHRP detects that all NHSs configured on the interface are in the down state, NHRP can change the interface state to down. However, if NHRP detects that any one of the NHSs configured on the interface is up, then it can change the state of the interface to up.
When the NHRP changes the interface state, other Cisco IOS services can react to the state change, for example:
If the interface state changes, the generic routing and encapsulation (GRE) interface generates IF-MIB notifications (traps) that report a LinkUp or LinkDown message. The system uses these traps to monitor the connectivity to the DMVPN cloud.
If the interface state changes to down, the Cisco IOS backup interface feature can be initiated to allow the system to use another interface to provide an alternative path to the failed primary path.
If the interface state changes to down, the system generates an update that is sent to all dynamic routing protocols. This provides a failover mechanism for dynamic routing when the multipoint GRE (mGRE) interface is down.
If the interface state changes to down, the system clears any static routes that use the mGRE interface as the next hop. This provides a failover mechanism for routing when the mGRE interface is down.
The interface state control feature works on both point-to-point and mGRE interfaces.
New 300-209 Exam Questions Updated Recently (4/July/2017):
NEW QUESTION 293
A company has a Flex VPN solution for remote access and one of their Cisco any Connect remote clients is having trouble connecting property. Which command verifies that packets are being encrypted and decrypted?
E. show crypto session detail
NEW QUESTION 294
Refer to the exhibit, which result of this command is true?
A. Makes the router generate a certificate signing request
B. Generates an RSA key called TRIALFOUR
C. It displays the RSA public keys of the router
D. It specifies self- signed enrollment for a trust point
Answer: A
NEW QUESTION 295
An engineer is attempting to establish a new site-to-site VPN connection. The tunnel terminates on an ASA 5506-X which is behind an ASA 5515-X. The engineer notices that the tunnel is not establishing. Which option is a potential cause?
A. Certificates were not configured
B. Diffie – Helman Group is not set
C. Access lists were not applied
D. NAT – traversal is not configured
Answer: D
NEW QUESTION 296
Which algorithm does ISAKMP use to securely derive encryption and integrity keys?
A. Diffie – Hellman
B. AES
C. ECDSA
D. RSA
E. 3DES
Answer: D
NEW QUESTION 297
Which purpose of configuring perfect Forward secret is true?
A. For every negotiation of a new phase 1 SA, the two gateways generate a new set of phase 2 keys.
B. For every negotiation of a new phase 2 SA, the two gateways generate a new set of phase 1 keys.
C. For every negotiation of a new phase 1 SA, the two gateways generate a new set of phase 1 keys.
D. For every negotiation of a new phase 2 SA, the two gateways generate a new set of phase 2 keys.
Answer: A
NEW QUESTION 298
An engineer has successfully established a phase 1 tunnel, but notices that no packets are decrypted on the head end side of the tunnel. What is a potential cause for this issue?
A. different phase 2 encryption
B. misconfigured DH group
C. disabled PFS
D. firewall blocking Phase 2 ESP or AH
Answer: A
NEW QUESTION 299
Which option describes traffic that will initiate a VPN connection?
A. trusted
B. external
C. internal
D. interesting
Answer: D
NEW QUESTION 300
……
P.S. These New 300-209 Exam Questions Were Just Updated From The Real 300-209 Exam, You Can Get The Newest 300-209 Dumps In PDF And VCE From — http://www.passleader.com/300-209.html (307q VCE and PDF)
Good Luck!
By the way, part of the new 307Q 300-209 dumps are available here:
https://drive.google.com/open?id=0B-ob6L_QjGLpVTNFVTRPdC0zTnM
Best Regards!