ETExamTower
Q69Network Security

Refer to the exhibit. An engineer is implementing a certificate-based VPN. What is the result of the existing configuration?

Question exhibit
← → navigate · a answer
Community votes
B
100% (4)
A
0% (0)
C
0% (0)
D
0% (0)
Discussion · 4
5
B: Configuring the IKEv2 Name Mangler Use this task to set the IKEv2 name mangler, which is used to derive a name for authorization requests and to obtain AAA preshared keys. The name is derived from specified parts of different forms of remote IKE identities or the EAP identity. enable configure terminal crypto ikev2 name-mangler mangler-name dn {common-name | country | domain | locality | organization | organization-unit | state} eap {all | dn {common-name | country | domain | locality | organization | organization-unit | state} | prefix | suffix {delimiter {. | @ | \}}} email {all | domain | username} fqdn {all | domain | hostname} end dn = Derives the name from any of the listed fields in the remote identity of type DN common-name country domain locality organization organization-unit state https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_ike2vpn/configuration/xe-16-10/sec-flex-vpn-xe-16-10-book/sec-cfg-flex-serv.html=
B 4
Selected Answer: B The correct answer is B. The "match identity certificate" command in the IKEv2 authorization policy is used to indicate that the OU (Organizational Unit) attribute of the IKEv2 peer certificate should be used as the identity when matching the policy. The OU attribute is set to "MANGLER" in this case. So, when an IKEv2 peer with a certificate that has an OU attribute of "MANGLER" tries to establish an IKEv2 SA, the router will use the OU attribute as the identity when matching the authorization policy. If the policy matches, the SA will be established successfully.
B 1
Selected Answer: B B is right
B 1
Selected Answer: B B. The OU of the IKEv2 peer certificate is used as the identity when matching an IKEv2 authorization policy.