156-215.81 · Question #683
You want to set up a VPN tunnel to a external gateway. You had to make sure that the IKE P2 SA will only be established between two subnets and not all subnets defined in the default VPN domain of…
The correct answer is B. In the SmartConsole create a dedicated VPN Community for both Gateways. Selecting the local. This answer is correct because this is the recommended way to configure a VPN tunnel between two subnets and not all subnets defined in the default VPN domain of your gateway. By creating a dedicated VPN Community, you can specify the VPN peers and the encryption settings for…
Question
You want to set up a VPN tunnel to a external gateway. You had to make sure that the IKE P2 SA will only be established between two subnets and not all subnets defined in the default VPN domain of your gateway.
Options
- AIn the SmartConsole create a dedicated VPN Community for both Gateways. On the
- BIn the SmartConsole create a dedicated VPN Community for both Gateways. Selecting the local
- CIn the SmartConsole create a dedicated VPN Community for both Gateways. On the Gateway
- DIn the SmartConsole create a dedicated VPN Community for both Gateways. Go to Security
How the community answered
(23 responses)- A17% (4)
- B74% (17)
- C4% (1)
- D4% (1)
Explanation
This answer is correct because this is the recommended way to configure a VPN tunnel between two subnets and not all subnets defined in the default VPN domain of your gateway. By creating a dedicated VPN Community, you can specify the VPN peers and the encryption settings for the VPN tunnel. By selecting the local gateway in the Community, you can set the VPN Domain to `User defined' and put in the local network that you want to include in the VPN tunnel. This way, you can limit the VPN traffic to the subnets that you want and avoid unnecessary encryption and decryption of other traffic. The other answers are not correct because they are either outdated or incorrect ways to configure a VPN tunnel between two subnets. Answer A and C are outdated methods that involve editing the user.def file, which is not recommended and can cause problems with the VPN configuration. Answer D is incorrect because creating an in-line layer rule with source and destination containing the two networks used for the IKE P2 SA will not affect the VPN tunnel establishment, but only the access control policy. The VPN column in the rule is used to specify the VPN direction, not the VPN Community name.
Topics
Community Discussion
No community discussion yet for this question.