ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 36 - JN0-636 discussion

Report
Export

Exhibit

You are trying to configure an IPsec tunnel between SRX Series devices in the corporate office and branch1. You have committed the configuration shown in the exhibit, but the IPsec tunnel is not establishing.

In this scenario, what would solve this problem.

A.
Add multipoint to the st0.0 interface configuration on the branch1 device.
Answers
A.
Add multipoint to the st0.0 interface configuration on the branch1 device.
B.
Change the IKE proposal-set to compatible on the branch1 and corporate devices.
Answers
B.
Change the IKE proposal-set to compatible on the branch1 and corporate devices.
C.
Change the local identity to inet advpn on the branch1 device.
Answers
C.
Change the local identity to inet advpn on the branch1 device.
D.
Change the IKE mode to aggressive on the branch1 and corporate devices.
Answers
D.
Change the IKE mode to aggressive on the branch1 and corporate devices.
Suggested answer: C

Explanation:

According to the Juniper documentation, the local identity for an IPsec VPN tunnel must match the remote identity of the peer device. The local identity can be configured as an IP address, a hostname, a distinguished name, or an advpn identifier. The advpn identifier is used for dynamic VPNs that support multiple remote endpoints. In the exhibit, the corporate device has the local identity configured as inet advpn, which means it expects the branch1 device to have the same remote identity. However, the branch1 device has the local identity configured as inet, which does not match the corporate device's remote identity. Therefore, the IKE negotiation fails and the IPsec tunnel is not established. To solve this problem, the local identity on the branch1 device should be changed to inet advpn, so that it matches the corporate device's remote identity. Reference: [Configuring an IKE Gateway] 1, [Configuring Local and Remote Identities] 2

1: https://www.juniper.net/documentation/us/en/software/junos/vpnipsec/topics/task/configuration/security-ike-gateway-configuring.html 2:

https://www.juniper.net/documentation/us/en/software/junos/vpn-ipsec/topics/topicmap/security-ipsec-vpn-identities.html

asked 18/09/2024
Dylan Johnson
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first