An election office must ensure only approved site subnets are protected in the DMVPN IPsec SAs rather than encrypting unintended flows. What control should they apply carefully?
Select an answer to reveal the explanation.
Short Explanation
Interesting-traffic ACLs are the guest list for encryption—only the subnets you name get the IPsec tuxedo. Widen that list carelessly and you encrypt (or break) flows you never meant to touch.
Full Explanation
IPsec proxy identities / crypto ACLs define which traffic selectors are protected in the SAs for DMVPN and related IPsec designs. Tight, mirrored selectors prevent unintended encryption and negotiation mismatches; overly broad or asymmetric ACLs cause missing protection or failed SAs. Storm control, PVLAN, and UDLD address other L2 problems and do not select DMVPN IPsec interesting traffic.