QuestionQ21

IPsec VPN

You must secure communications between a mobile command center, using a 5G mobile ISP behind CGNAT, and an SRX Series Firewall at headquarters.

Which two actions should be completed on the SRX Series Firewall for this scenario?

Choose two
Explanation

A CGNAT-hosted mobile endpoint requires NAT Traversal (NAT-T), which encapsulates IKE and ESP in UDP so address and port translation does not invalidate IPsec traffic. For an SRX dynamic endpoint VPN using IKEv1, the IKE policy must use aggressive mode so the unknown-address peer can be identified during negotiation. IKEv2 does not use aggressive mode, and Dead Peer Detection is optional liveness monitoring rather than the required dynamic-endpoint setting. Juniper: IPsec VPN configuration overview

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!