ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 92 - JN0-636 discussion

Report
Export

you are connecting two remote sites to your corporate headquarters site. You must ensure that traffic passes corporate headquarter.

A.
In this scenario, which VPN should be used?
Answers
A.
In this scenario, which VPN should be used?
B.
full mesh IPsec VPNs with tunnels between all sites
Answers
B.
full mesh IPsec VPNs with tunnels between all sites
C.
a full mesh Layer 3 VPN with the BGP route reflector behind the corporate firewall device
Answers
C.
a full mesh Layer 3 VPN with the BGP route reflector behind the corporate firewall device
D.
a Layer 3 VPN with the corporate firewall acting as the hub device
Answers
D.
a Layer 3 VPN with the corporate firewall acting as the hub device
E.
hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device
Answers
E.
hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device
Suggested answer: D

Explanation:

You are connecting two remote sites to your corporate headquarters site. You must ensure that traffic passes through the corporate headquarters. In this scenario, the VPN that should be used is:

D) Hub-and-spoke IPsec VPN with the corporate firewall acting as the hub device. A hub-and-spoke IPsec VPN is a type of VPN that connects multiple remote sites to a central site, or hub, over a public network. The hub site acts as a gateway for the remote sites and provides security and routing services. The remote sites, or spokes, communicate with each other through the hub site. The hub site and the spoke sites use IPsec tunnels to encrypt and authenticate the traffic between them. A hub-and-spoke IPsec VPN is suitable for connecting two remote sites to your corporate headquarters site, because it allows you to control the traffic flow and enforce security policies at the hub site. The corporate firewall can act as the hub device and provide IPsec VPN services to the remote sites1.

The other options are incorrect because:

A) Full mesh IPsec VPNs with tunnels between all sites. A full mesh IPsec VPN is a type of VPN that connects every site to every other site over a public network. Each site has an IPsec tunnel with every other site, forming a mesh topology. A full mesh IPsec VPN provides direct and secure communication between any pair of sites, but it also requires a large number of IPsec tunnels and complex configuration. A full mesh IPsec VPN is not suitable for connecting two remote sites to your corporate headquarters site, because it does not ensure that traffic passes through the corporate headquarters site, and it may introduce unnecessary overhead and complexity2.

B) A full mesh Layer 3 VPN with the BGP route reflector behind the corporate firewall device. A full mesh Layer 3 VPN is a type of VPN that uses MPLS and BGP to provide Layer 3 connectivity and routing between multiple sites over a service provider's network. Each site has a BGP session with every other site, forming a full mesh topology. A BGP route reflector is a device that reduces the number of BGP sessions required in a full mesh topology by reflecting routes between its clients. A full mesh Layer 3 VPN with the BGP route reflector behind the corporate firewall device is not suitable for connecting two remote sites to your corporate headquarters site, because it does not ensure that traffic passes through the corporate firewall device, and it may require additional configuration and coordination with the service provider3.

C) A Layer 3 VPN with the corporate firewall acting as the hub device. A Layer 3 VPN is a type of VPN that uses MPLS and BGP to provide Layer 3 connectivity and routing between multiple sites over a service provider's network. A Layer 3 VPN can have different topologies, such as full mesh, hub-andspoke, or partial mesh. A Layer 3 VPN with the corporate firewall acting as the hub device is not suitable for connecting two remote sites to your corporate headquarters site, because the corporate firewall may not support MPLS and BGP, and it may require additional configuration and coordination with the service provider3.

Reference:

Hub-and-Spoke VPNs Overview

Full Mesh VPNs Overview

Layer 3 VPNs Overview

asked 18/09/2024
bert toger
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first