QuestionQ16

IPsec VPN

Question Image

A new site-to-site VPN tunnel has been configured. The exhibit displays the security IPsec statistics output for the particular tunnel index on one tunnel-end device.

Which two statements are correct for this scenario?

Choose two
Explanation

Nonzero ESP authentication and decryption failures indicate that ESP-protected packets do not match the configured authentication or encryption parameters, so the ESP configuration is incorrect between the tunnel endpoints. The encrypted and decrypted packet and byte counters are all zero, meaning no traffic has been successfully processed through the tunnel. Zero AH authentication failures do not indicate an AH configuration problem.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!