ExamGecko
Question list
Search
Search

Related questions











Question 237 - PCNSE discussion

Report
Export

A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled.

What action should the engineer take?

A.
Add an authentication algorithm in the IPSec Crypto profile.
Answers
A.
Add an authentication algorithm in the IPSec Crypto profile.
B.
Enable PFS under the IPSec Tunnel advanced options.
Answers
B.
Enable PFS under the IPSec Tunnel advanced options.
C.
Select the appropriate DH Group under the IPSec Crypto profile.
Answers
C.
Select the appropriate DH Group under the IPSec Crypto profile.
D.
Enable PFS under the IKE gateway advanced options
Answers
D.
Enable PFS under the IKE gateway advanced options
Suggested answer: C

Explanation:

PFS (Perfect Forward Secrecy) is a feature that ensures that the encryption keys used for each IPSec session are not derived from previous keys. This provides more security in case one key is compromised. To enable PFS, the administrator needs to select the appropriate DH (Diffie-Hellman) Group under the IPSec Crypto profile that is applied to the IPSec tunnel. The DH Group determinesthe strength of the key exchange and should match on both ends of the tunnel1. The other optionsdo not enable PFS. The authentication algorithm in the IPSec Crypto profile is used to verify theintegrity of the IPSec packets. The PFS option under the IPSec Tunnel advanced options or the IKE gateway advanced options does not exist in the WebUI. Reference: 1: https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-admin/vpn/site-to-site-vpn/configure-the- ipsec-crypto-profile

asked 23/09/2024
Jonathan Dowds
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first