nerdexam
Check_Point

156-585 · Question #59

Joey is configuring a site-to-site VPN with his business partner. On Joey's site he has a Check Point R80.10 Gateway and his partner uses Cisco ASA 5540 as a gateway. Joey's VPN domain on the Check…

The correct answer is B. Tunnel fails on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation. See the full explanation below for the reasoning.

Question

Joey is configuring a site-to-site VPN with his business partner. On Joey's site he has a Check Point R80.10 Gateway and his partner uses Cisco ASA 5540 as a gateway. Joey's VPN domain on the Check Point Gateway object is manually configured with a group object that contains two network objects:

VPN_Domain3 = 192.168.14.0/24 VPN_Domain4 = 192.168.15.0/24 Partner's site ACL as viewed from "show run" access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.14.0 255.255.255.0 access-list JOEY-VPN extended permit ip 172.26.251.0 255.255.255.0 192.168.15.0 255.255.255.0 When they try to establish VPN tunnel, it fails. What is the most likely cause of the failure given the information provided?

Options

  • ATunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation.
  • BTunnel fails on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation.
  • CTunnel fails on Joey's site, because he misconfigured IP address of VPN peer.
  • DTunnel falls on partner site. It is likely that the Cisco ASA 5540 will reject the Phase 2 negotiation

How the community answered

(43 responses)
  • A
    14% (6)
  • B
    77% (33)
  • C
    5% (2)
  • D
    5% (2)

Community Discussion

No community discussion yet for this question.

Full 156-585 Practice