Q28Secure Network Access, Visibility, and Enforcement
A network engineer sets up a site-to-site VPN with a colleague. During testing, the engineer finds that only Phase 1 is up and application traffic cannot pass. Which configuration parameter must be verified on each device?
← → navigate · a answer
Community votes
Discussion · 4
C 3
Selected Answer: C
I think the answer is C. encryption domain - this is the "interesting traffic" that is supposed to be encrypted. If I'm not mistaken, the other options are all done in phase 1 and phase 1 is up.
C 2
Selected Answer: C
ike phase 1 succeeds so that means the peer ips are fine including the preshared key
phase 2 is the encryption domain.
Answer C
C 2
Selected Answer: C
As mentioned by others, C is correct because Phase 1 is already up, Phase 2 is all 'crypto acl or proxy ID', so the 'interesting traffic' is not matching, so check your encryption domain.
1
Configure the IKEv1 policy
!
crypto ikev1 policy 10
authentication pre-share
encryption aes-256
hash sha
group 5
lifetime 3600
from https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/215884-configure-a-site-to-site-vpn-tunnel-with.html
peer IP address is the correct answer. It is not a belief, just proof.