An engineer configured a site-to-site crypto map based policy VPN. After adding a new internal subnet behind the local router, traffic from that subnet is not traversing the VPN. Which single root cause explains this behavior for a policy-based VPN?
Choose an answer
Tap an option to check your answer.
Correct answer: The crypto ACL (traffic selector) does not include the new subnet, so traffic is not matched for encryption.
Why this is the answer
In a policy-based VPN, the crypto access control list (ACL), also known as the traffic selector, explicitly defines which traffic should be encrypted and sent over the VPN tunnel. If a new internal subnet is added, and its network is not included in this crypto ACL, traffic originating from or destined for that subnet will not be identified as needing encryption by the VPN policy. Consequently, this traffic will not traverse the VPN tunnel. Policy-based VPNs can handle additional subnets as long as they are correctly defined in the crypto ACL. Crypto maps support both IPv4 and IPv6, so the IPv6 claim is incorrect. While NAT exemption is often configured alongside VPNs, the primary issue for policy-based VPNs not encrypting traffic from a new subnet is the absence of that subnet in the crypto ACL, not solely a NAT exemption issue.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed