ExamGecko
Question list
Search
Search

Related questions











Question 20 - PCNSC discussion

Report
Export

A customer is adding a new site-to-site tunnel from a Palo Alto Networks NGFW to a third party with a policy based VPN peer After the initial configuration is completed and the changes are committed, phase 2 fails to establish

Which two changes may be required to fix the issue? (Choose two)

A.
Verity that the certificate used tor authentication is installed.
Answers
A.
Verity that the certificate used tor authentication is installed.
B.
Verify that PFS is enabled on both ends
Answers
B.
Verify that PFS is enabled on both ends
C.
Enable the NAT Traversal advanced option.
Answers
C.
Enable the NAT Traversal advanced option.
D.
Add proxy IDs to the iPsec tunnel configuration
Answers
D.
Add proxy IDs to the iPsec tunnel configuration
Suggested answer: B, D

Explanation:

When configuring a site-to-site VPN between a Palo Alto Networks Next-Generation Firewall (NGFW) and a third-party device with a policy-based VPN peer, Phase 2 failures can often be attributed to configuration mismatches or missing parameters. Here are the two changes that may be required to fix the issue:

B . Verify that PFS is enabled on both ends: Perfect Forward Secrecy (PFS) is a method that ensures the security of cryptographic keys. Both ends of the VPN tunnel need to agree on whether PFS is used. If PFS is enabled on one side but not the other, Phase 2 will fail. Verify the PFS settings and ensure they are matched on both the Palo Alto firewall and the third-party VPN device.

D . Add proxy IDs to the IPsec tunnel configuration: Proxy IDs (or traffic selectors) define the specific local and remote IP ranges that are allowed to communicate through the VPN tunnel. They are particularly crucial when dealing with policy-based VPNs. If the proxy IDs are not correctly configured, Phase 2 negotiations will fail. Add the appropriate proxy IDs to the IPsec tunnel configuration to match the policy-based VPN settings of the third-party device.

Palo Alto Networks - Configuring Site-to-Site VPN Between Palo Alto Networks and a Third-Party Firewall: https://docs.paloaltonetworks.com

Palo Alto Networks - VPN Configuration Guidelines: https://knowledgebase.paloaltonetworks.com

asked 23/09/2024
Kees den Dekker
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first