Q69Network Security
Refer to the exhibit. An engineer is implementing a certificate-based VPN. What is the result of the existing configuration?
← → navigate · a answer
Community votes
Discussion · 4
5
B:
Configuring the IKEv2 Name Mangler
Use this task to set the IKEv2 name mangler, which is used to derive a name for authorization requests and to obtain AAA preshared keys. The name is derived from specified parts of different forms of remote IKE identities or the EAP identity.
enable
configure terminal
crypto ikev2 name-mangler mangler-name
dn {common-name | country | domain | locality | organization | organization-unit | state}
eap {all | dn {common-name | country | domain | locality | organization | organization-unit | state} | prefix | suffix {delimiter {. | @ | \}}}
email {all | domain | username}
fqdn {all | domain | hostname}
end
dn = Derives the name from any of the listed fields in the remote identity of type DN
common-name
country
domain
locality
organization
organization-unit
state
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16-10/sec-flex-vpn-xe-16-10-book/sec-cfg-flex-serv.html=
B 4
Selected Answer: B
The correct answer is B.
The "match identity certificate" command in the IKEv2 authorization policy is used to indicate that the OU (Organizational Unit) attribute of the IKEv2 peer certificate should be used as the identity when matching the policy. The OU attribute is set to "MANGLER" in this case.
So, when an IKEv2 peer with a certificate that has an OU attribute of "MANGLER" tries to establish an IKEv2 SA, the router will use the OU attribute as the identity when matching the authorization policy. If the policy matches, the SA will be established successfully.
B 1
Selected Answer: B
B is right
B 1
Selected Answer: B
B. The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.