ExamGecko
Question list
Search
Search

Related questions











Question 333 - PCNSE discussion

Report
Export

An administrator configures a site-to-site IPsec VPN tunnel between a PA-850 and an external customer on their policy-based VPN devices.

What should an administrator configure to route interesting traffic through the VPN tunnel?

A.
Proxy IDs
Answers
A.
Proxy IDs
B.
GRE Encapsulation
Answers
B.
GRE Encapsulation
C.
Tunnel Monitor
Answers
C.
Tunnel Monitor
D.
ToS Header
Answers
D.
ToS Header
Suggested answer: A

Explanation:

An administrator should configure proxy IDs to route interesting traffic through the VPN tunnel when the peer device is a policy-based VPN device. Proxy IDs are used to identify the traffic that belongs to a particular IPSec VPN and to direct it to the appropriate tunnel. Proxy IDs consist of a local IP address, a remote IP address, and an application (protocol and port numbers). Each proxy ID is considered to be a VPN tunnel and is counted towards the IPSec VPN tunnel capacity of the firewall. Proxy IDs are required for IKEv1 VPNs and optional for IKEv2 VPNs. If the proxy ID is not configured, the firewall uses the default values of source IP: 0.0.0.0/0, destination IP: 0.0.0.0/0, and application: any, which may not match the peer's policy and result in a failure to establish the VPN connection.Reference:

Proxy ID for IPSec VPN

Set Up an IPSec Tunnel

asked 23/09/2024
xingrui li
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first