PrepAway - Latest Free Exam Questions & Answers

Which statement is correct regarding the group configuration on the current key server for group 1?

You have an existing group VPN established in your internal network using the group-id 1.
You have been asked to configure a second group using the group-id 2. You must ensure
that the key server for group 1 participates in group 2 but is not the key server for that
group. Which statement is correct regarding the group configuration on the current key
server for group 1?

PrepAway - Latest Free Exam Questions & Answers

A.
You must configure both groups at the [edit security group-vpn] hierarchy.

B.
You must configure both groups at the [edit security ipsec vpn] hierarchy.

C.
You must configure both groups at the [edit security group-vpn member] hierarchy.

D.
You must configure both groups at the [edit security ike] hierarchy.

Explanation:

5 Comments on “Which statement is correct regarding the group configuration on the current key server for group 1?

  1. Tom Brady says:

    From the KB posted by RWJ, I disagree that it is A. Note there is only “grp1” not “grp1” and “grp2”

    This is very tricky on wording. You configure a single group under [edit security group-vpn], which makes me think A is wrong.

    Under the group however, is where you would configure multiple match-policy’s p1, p2, p2.

    In “C” the group is called member and that edit stanza is valid. If this shows up on the actual exam I’m going with “C”




    0



    0

Leave a Reply