PrepAway - Latest Free Exam Questions & Answers

Which of the following can be done to resolve this problem?

After implementing the IKEv2 tunnel, it was observed that remote users on the
192.168.33.0/24 network are unable to access the internet. Which of the following can be done
to resolve this problem?

PrepAway - Latest Free Exam Questions & Answers

A.
Change the Diffie-Hellman group on the headquarter ASA to group5forthe dynamic crypto
map

B.
Change the remote traffic selector on the remote ASA to 192.168.22.0/24

C.
Change to an IKEvI configuration since IKEv2 does not support a full tunnel with static peers

D.
Change the local traffic selector on the headquarter ASA to 0.0.0.0/0

E.
Change the remote traffic selector on the headquarter ASA to 0.0.0.0/0

Explanation:
The traffic selector is used to determine which traffic should be protected (encrypted over the
IPSec tunnel). We want this to be specific, otherwise Internet traffic will also be sent over the
tunnel and most likely dropped on the remote side. Here, we just want to protect traffic from
192.168.33.0/24 to 192.168.22.0/24.

5 Comments on “Which of the following can be done to resolve this problem?

  1. Ace says:

    I think the question is poorly worded. If they were expecting us to choose answer B, then the scenerio context about tunneling all traffic should be removed or negated. As the question is worded I think Grzeg is correct. However checking other internet sources, it appears they expect us to answer B.




    0



    0
  2. Choppy says:

    “All traffic from the remote site must be sent over the tunnel including internet traffic.”.

    This would make answer D a valid answer, B wouldn’t allow internet traffic to go over the tunnel.




    0



    0

Leave a Reply