ExamGecko
Question list
Search
Search

Related questions











Question 231 - PCNSE discussion

Report
Export

A security engineer received multiple reports of an IPSec VPN tunnel going down the night before.

The engineer couldn't find any events related to VPN under system togs.

What is the likely cause?

A.
Dead Peer Detection is not enabled.
Answers
A.
Dead Peer Detection is not enabled.
B.
Tunnel Inspection settings are misconfigured.
Answers
B.
Tunnel Inspection settings are misconfigured.
C.
The Tunnel Monitor is not configured.
Answers
C.
The Tunnel Monitor is not configured.
D.
The log quota for GTP and Tunnel needs to be adjusted
Answers
D.
The log quota for GTP and Tunnel needs to be adjusted
Suggested answer: C

Explanation:

This means that the firewall does not have a mechanism to monitor the status of the IPSec VPN tunnel and generate logs when it goes down or up. The Tunnel Monitor is an optional feature that can be enabled on each IPSec tunnel interface and it uses ICMP probes to check the connectivity of the tunnel peer. If the firewall does not receive a response from the peer after a specified number of retries, it marks the tunnel as down and logs an event1.

asked 23/09/2024
Dang Xuan Bao
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first