QuestionQ16

Advanced IPsec VPNs

Click the Exhibit button.

Question Image

You are troubleshooting a newly configured IPsec VPN between your corporate office and the RemoteSite1 SRX Series device. The VPN is currently not establishing. The RemoteSite1 device receives an IP address for its gateway interface through DHCP.

Referring to the exhibit, which action will resolve this issue?

  • A On the RemoteSite1 device, change the IKE gateway external interface to st0.0.
  • B On both devices, change the IKE version to use version 2 only.
  • C On both devices, change the IKE policy proposal set to basic.
  • D On both devices, change the IKE policy mode to aggressive.
Explanation

For an IKEv1 VPN using pre-shared keys, a peer with a dynamically assigned external IP address must use aggressive mode rather than main mode. Aggressive mode sends the peer identity early in the exchange, allowing the receiving gateway to select the appropriate policy and pre-shared key for the dynamic peer.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!