ETExamTower
Q28Secure Network Access, Visibility, and Enforcement

A network engineer sets up a site-to-site VPN with a colleague. During testing, the engineer finds that only Phase 1 is up and application traffic cannot pass. Which configuration parameter must be verified on each device?

← → navigate · a answer
Community votes
C
100% (4)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 4
C 3
Selected Answer: C I think the answer is C. encryption domain - this is the "interesting traffic" that is supposed to be encrypted. If I'm not mistaken, the other options are all done in phase 1 and phase 1 is up.
C 2
Selected Answer: C ike phase 1 succeeds so that means the peer ips are fine including the preshared key phase 2 is the encryption domain. Answer C
C 2
Selected Answer: C As mentioned by others, C is correct because Phase 1 is already up, Phase 2 is all 'crypto acl or proxy ID', so the 'interesting traffic' is not matching, so check your encryption domain.
1
Configure the IKEv1 policy ! crypto ikev1 policy 10 authentication pre-share encryption aes-256 hash sha group 5 lifetime 3600 from https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/215884-configure-a-site-to-site-vpn-tunnel-with.html peer IP address is the correct answer. It is not a belief, just proof.