County courts are migrating DMVPN IPsec protection from IKEv1 to IKEv2. What is a primary reason to prefer IKEv2 for modern crypto hygiene on the overlay?
Select an answer to reveal the explanation.
Short Explanation
IKEv2 is the cleaner handshake for locking the DMVPN tunnels — fewer round trips, modern crypto expectations, better hygiene than old IKEv1. mGRE still needs IPsec for encryption on Internet transports; IKEv2 does not magically encrypt by itself.
Full Explanation
Protecting DMVPN on Internet transports relies on IPsec, and IKEv2 is the preferred key-exchange evolution over IKEv1: more efficient negotiation, improved reliability features, and alignment with current cryptographic guidance. mGRE alone is not encryption. IKEv2 does not mandate Phase 1-only DMVPN, and PSK remains possible where policy allows — migration does not require abandoning DMVPN for MPLS. Courts should standardize on IKEv2 profiles for overlay protection.