ExamGecko
Question list
Search
Search

Related questions











Question 348 - PCNSE discussion

Report
Export

A firewall administrator is configuring an IPSec tunnel between Site A and Site B. The Site A firewall uses a DHCP assigned address on the outside interface of the firewall, and the Site B firewall uses a static IP address assigned to the outside interface of the firewall. However, the use of dynamic peering is not working.

Refer to the two sets of configuration settings provided. Which two changes will allow the configurations to work? (Choose two.)

Site A configuration:

A.
Enable NAT Traversal on Site B firewall
Answers
A.
Enable NAT Traversal on Site B firewall
B.
Configure Local Identification on Site firewall
Answers
B.
Configure Local Identification on Site firewall
C.
Disable passive mode on Site A firewall
Answers
C.
Disable passive mode on Site A firewall
D.
Match IKE version on both firewalls.
Answers
D.
Match IKE version on both firewalls.
Suggested answer: C, D

Explanation:

The image shows an IKE Gateway configuration where Site B is set to IKEv1 only mode, and passive mode is not enabled. For dynamic peering to work when Site A is using a DHCP assigned address:

Passive mode on Site A needs to be disabled. In passive mode, the firewall will not initiate the IKE negotiation and will only respond to negotiation requests from the peer. Since Site A has a dynamic IP, it must be able to initiate the connection to Site B, which has a static IP.

Matching the IKE version between Site A and Site B is also necessary for successful IPSec tunnel establishment. Since Site B is set to IKEv1 only mode, Site A also needs to be configured to use IKEv1 to ensure that both sites are using the same version for the IKE negotiation process.

NAT Traversal is used when there are NAT devices between the two endpoints, but there's no indication that this is the case here. Additionally, local identification on Site A is not necessarily related to the issue with dynamic peering not working.

asked 23/09/2024
nebaba monda
42 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first