PrepAway - Latest Free Exam Questions & Answers

Author: seenagape

Which of these is the appropriate configuration on the Cisco ASA adaptive security…?

Refer to the exhibit.

Client1 has an IPsec VPN tunnel established to a Cisco ASA adaptive security appliance in
Chicago. The remote access VPN client wants to access www.cisco.com, but split
tunneling is disabled. Which of these is the appropriate configuration on the Cisco ASA
adaptive security appliance if the VPN client’s public IP address is 209.165.201.10 and it
is assigned a private address from 192.168.1.0/24?

What could be the potential problem?

You are trying to set up a site-to-site IPsec tunnel between two Cisco ASA adaptive
security appliances, but you are not able to pass traffic. You try to troubleshoot the
issue by enabling debug crypto isakmp and see the following messages:
CiscoASA# debug crypto isakmp
[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, Tunnel RejecteD. Conflicting
protocols specified by tunnel-group and group-policy
[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, QM FSM error (P2 struct
&0xb0cf31e8, mess id 0x97d965e5)!
[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, Removing peer from
correlator table failed, no match!
What could be the potential problem?


Page 570 of 4,656« First...102030...568569570571572...580590600...Last »