156-585 · Question #59
Joey is configuring a site-to-site VPN with his business partner. On Joey's site he has a Check Point R80.10 Gateway and his partner uses Cisco ASA 5540 as a gateway. Joey's VPN domain on the Check…
The correct answer is B. Tunnel fails on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation. See the full explanation below for the reasoning.
Question
Joey is configuring a site-to-site VPN with his business partner. On Joey's site he has a Check Point R80.10 Gateway and his partner uses Cisco ASA 5540 as a gateway. Joey's VPN domain on the Check Point Gateway object is manually configured with a group object that contains two network objects:
VPN_Domain3 = 192.168.14.0/24 VPN_Domain4 = 192.168.15.0/24 Partner's site ACL as viewed from "show run" access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.14.0 255.255.255.0 access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.15.0 255.255.255.0 When they try to establish VPN tunnel, it fails. What is the most likely cause of the failure given the information provided?
Options
- ATunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation.
- BTunnel fails on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation.
- CTunnel fails on Joey's site, because he misconfigured IP address of VPN peer.
- DTunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation
How the community answered
(43 responses)- A14% (6)
- B77% (33)
- C5% (2)
- D5% (2)
Community Discussion
No community discussion yet for this question.