QuestionQ82

Multinode High Availability (HA)

Select the Exhibit button.

Question Image

You have deployed a pair of SRX Series devices in a multinode HA environment. You must enable IPsec encryption on the interchassis link.

Referring to the exhibit, which three steps are needed to enable ICL encryption?

Choose three
  • A Install the Junos IKE package on both nodes.
  • B Enable OSPF for both interchassis link interfaces and turn on the dynamic-neighbors parameter.
  • C Configure a VPN profile for the HA traffic and apply to both nodes.
  • D Enable HA link encryption in the IPsec profile on both nodes.
  • E Enable HA link encryption in the IKE profile on both nodes.
Explanation

Multinode HA link encryption requires the unified IKE process supplied by the junos-ike package where that package is not already installed. The HA peer configuration must reference an IPsec VPN profile, and the corresponding IPsec VPN on each node must be configured with ha-link-encryption to secure ICL traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!