PrepAway - Latest Free Exam Questions & Answers

Category: 350-018

CCIE Security Exam (4.0)

What could be the potential problem?

You are trying to set up a site-to-site IPsec tunnel between two Cisco ASA adaptive security appliances, but you are not able to pass traffic. You try to troubleshoot the issue by enabling debug crypto isakmp and see the following messages:

CiscoASA# debug crypto isakmp

[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, Tunnel Rejected: Conflicting protocols specified by tunnel-group and group-policy

[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, QM FSM error (P2 struct &0xb0cf31e8, mess id 0x97d965e5)!

[IKEv1]: Group = 209.165.200.231, IP = 209.165.200.231, Removing peer from correlator table failed, no match!

What could be the potential problem?

What will this configuration for an IDSM-2 module do?

What will this configuration for an IDSM-2 module do?

intrusion-detection module 6 management-port access-vlan 36

intrusion-detection module 6 data-port 1 capture

intrusion-detection module 6 data-port 1 capture allowed-vlan 1-10, 36, 124

!

vlan access-map IDSM-2 10

match ip address 150

action forward capture

vlan access-map IDSM-2 20

match ip address 151

action forward

!

vlan filter IDSM-2 vlan-list 1 -10, 36, 124

!

access-list 150 permit tcp any 10.1.1.0 0.0.0.255

access-list 151 permit ip any any


Page 46 of 65« First...102030...4445464748...60...Last »