ETExamTower
Q55Network SecurityMultiple answers

Which two conditions must be met for stateful IPsec failover? (Choose two.)

Select 2 answers.
← → navigate · a answer
Community votes
C
50% (8)
E
50% (8)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 18
20
CE https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnav/configuration/15-mt/sec-vpn-availability-15-mt-book/sec-state-fail-ipsec.html#:~:text=Stateful%20failover%20for%20IPsec%20requires,accelerator%20or%20identical%20encryption%20accelerators. Restrictions for Stateful Failover for IPsec When setting up redundancy for a VPN, these restrictions apply: Both the active and standby devices must be running the exact same version of the Cisco IOS software, and both the active and standby devices must be connected through a hub or switch.
7
C and E Restrictions for Stateful Failover for IPsec When setting up redundancy for a VPN, these restrictions apply: Both the active and standby devices must run the identical version of the Cisco IOS software, and both the active and standby devices must be connected via a hub or switch.
3
C and E are correct. Device Requirements Stateful failover for IPsec requires that your network contains two identical routers that can be either the primary or secondary device. Both routers should be the same type of device, have the same CPU and memory, and have either no encryption accelerator or identical encryption accelerators. Restrictions for Stateful Failover for IPsec When setting up redundancy for a VPN, these restrictions apply: Both the active and standby devices must run the identical version of the Cisco IOS software, and both the active and standby devices must be connected via a hub or switch.
C, E 3
Selected Answer: CE Should be C & E
2
C and E for sure
C, E 2
Selected Answer: CE The IKE and IPsec configuration that is set up on the active device must be duplicated on the standby device. Both the active and standby devices must run the identical version of the Cisco IOS software, and both the active and standby devices must be connected via hub or switch. Stateful failover for IPsec requires that your network has two identical routers that can be either the primary or secondary device.
2
C,E Prerequisites for Stateful Failover for IPsec Complete, Duplicate IPsec and IKE Configuration on the Active and Standby Devices This document assumes that you have a complete IKE and IPsec configuration. The IKE and IPsec configuration that is set up on the active device must be duplicated on the standby device. That is, the crypto configuration must be identical with respect to Internet Security Association and Key Management Protocol (ISAKMP) policy, ISAKMP keys (preshared), IPsec profiles, IPsec transform sets, all crypto map sets that are used for stateful failover, all access control lists (ACLs) that are used in match address statements on crypto map sets, all AAA configurations used for crypto, client configuration groups, IP local pools used for crypto, and ISAKMP profiles.
C, E 2
Selected Answer: CE Check the prerequisites
C, E 2
Selected Answer: CE Prerequisites for Stateful Failover for IPsec Complete, Duplicate IPsec and IKE Configuration on the Active and Standby Devices Both the active and standby devices must run the identical version of the Cisco IOS software, and both the active and standby devices must be connected via a hub or switch.
2
CE Stateful failover for IPsec is a feature that lets a standby device take over the duties of an active device if there is a failure. For this to work, some conditions have to be met: -The IPsec configuration that is set up on the active device must also be copied to the standby device. This includes the IPsec policies, access control lists, and other settings that are needed for the IPsec connections to work. -The active and standby devices must run the same version of the Cisco IOS software and must be the same type of device. This is needed to make sure the standby device can handle the same IPsec connections as the active device and that any problems can be fixed with the same software version.
1
C & E are the correct answer. I deploy Cisco firewalls for a living and C & E are absolutely the correct answers.
1
CE absolutely
1
Technically B and C are correct.. When the FW HA is upgraded, for a time being both the units are running different OS versions. Still the failover is stateful
1
Also the doc doesn't say that they need to be on the same version: Device Requirements Stateful failover for IPsec requires that your network has two identical routers that can be either the primary or secondary device. Both routers should be the same type of device, have the same CPU and memory, and have either no encryption accelerator or identical encryption accelerators. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_conn_vpnav/configuration/15-mt/sec-vpn-availability-15-mt-book/sec-state-fail-ipsec.html#GUID-484562B6-A113-4901-A630-37869F8494D8
C, E 1
Selected Answer: CE CE because even if sometimes B may work, it's definitely not best practice and you shouldn't be doing it.
1
Device Requirements Stateful failover for IPsec requires that your network has two identical routers that can be either the primary or secondary device. Both routers should be the same type of device, have the same CPU and memory, and have either no encryption accelerator or identical encryption accelerators. Restrictions for Stateful Failover for IPsec When setting up redundancy for a VPN, these restrictions apply: Both the active and standby devices must run the identical version of the Cisco IOS software, and both the active and standby devices must be connected via a hub or switch. "C and E"
C, E 1
Selected Answer: CE C and E are correct
C, E 1
Selected Answer: CE Correct Answers are C and E