Which authentication, encryption, and integrity combination is used for IPsec tunnels in Cisco SD-WAN?
Choose an answer
Tap an option to check your answer.
Correct answer: Authentication is 2048-bit key; encryption is AES-256 cipher, and integrity is ESP, HMAC-SHA1..
Why this is the answer
Cisco SD-WAN uses strong cryptographic standards for IPsec tunnels to ensure secure communication. The correct combination specifies a 2048-bit key for authentication, which provides a robust level of security for key exchange. AES-256 is the standard encryption cipher, offering a high level of confidentiality. ESP (Encapsulating Security Payload) is the IPsec protocol used for both encryption and integrity, and HMAC-SHA1 is the specific hashing algorithm for integrity checking, ensuring data has not been tampered with. Options with 1024-bit keys or AES-128 are less secure than the default or recommended settings. While HMAC-MD5 can be used, HMAC-SHA1 is generally preferred for its stronger collision resistance.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed