nerdexam
Oracle

1Z0-1072-20 · Question #135

Which two statements are true about Oracle Cloud Infrastructure IPSec VPN Connect?

The correct answer is A. Each OCI IPSec VPN consists of multiple redundant IPSec tunnels C. OCI IPSec VPN can be configured in tunnel mode only. VPN Connect provides a site-to-site IPSec VPN between your on-premises network and your virtual cloud network (VCN). The IPSec protocol suite encrypts IP traffic before the packets are transferred from the source to the destination and decrypts the traffic when it arrives. On…

Implement OCI Networking

Question

Which two statements are true about Oracle Cloud Infrastructure IPSec VPN Connect?

Options

  • AEach OCI IPSec VPN consists of multiple redundant IPSec tunnels
  • BOCI IPSec VPN tunnel supports only static routes to route traffic
  • COCI IPSec VPN can be configured in tunnel mode only
  • DOCI IPSec VPN can be configured in trans port mode only

How the community answered

(23 responses)
  • A
    74% (17)
  • B
    17% (4)
  • D
    9% (2)

Explanation

VPN Connect provides a site-to-site IPSec VPN between your on-premises network and your virtual cloud network (VCN). The IPSec protocol suite encrypts IP traffic before the packets are transferred from the source to the destination and decrypts the traffic when it arrives. On general, IPSec can be configured in the following modes: Transport mode: IPSec encrypts and authenticates only the actual payload of the packet, and the header information stays intact. Tunnel mode (supported by Oracle): IPSec encrypts and authenticates the entire packet. After encryption, the packet is then encapsulated to form a new IP packet that has different header Oracle Cloud Infrastructure supports only the tunnel mode for IPSec VPNs. Each Oracle IPSec VPN consists of multiple redundant IPSec tunnels. For a given tunnel, you can use either Border Gateway Protocol (BGP) dynamic routing or static routing to route that tunnel's traffic. More details about routing follow. IPSec VPN site-to-site tunnels offer the following advantages: Public internet lines are used to transmit data, so dedicated, expensive lease lines from one site to another aren't necessary. The internal IP addresses of the participating networks and nodes are hidden from external users. The entire communication between the source and destination sites is encrypted, significantly lowering the chances of information theft.

Topics

#IPSec VPN#redundant tunnels#tunnel mode#VPN configuration

Community Discussion

No community discussion yet for this question.

Full 1Z0-1072-20 Practice