210-260 · Question #66
Refer to the exhibit. While troubleshooting site-to-site VPN, you issued the show crypto ipsec sa command. What does the given output show?
The correct answer is B. IPSec Phase 2 is established between 10.1.1.1 and 10.1.1.5. Once the secure tunnel from phase 1 has been established, we will start phase 2. In this phase the two firewalls will negotiate about the IPsec security parameters that will be used to protect the traffic within the tunnel. In short, this is what happens in phase 2: Negotiate…
Question
Refer to the exhibit. While troubleshooting site-to-site VPN, you issued the show crypto ipsec sa command. What does the given output show?
Exhibit
Options
- AISAKMP security associations are established between 10.1.1.5 and 10.1.1.1
- BIPSec Phase 2 is established between 10.1.1.1 and 10.1.1.5
- CIKE version 2 security associations are established between 10.1.1.1 and 10.1.1.5
- DIPSec Phase 2 is down due to a mismatch between encrypted and decrypted packets
How the community answered
(29 responses)- A3% (1)
- B79% (23)
- C14% (4)
- D3% (1)
Explanation
Once the secure tunnel from phase 1 has been established, we will start phase 2. In this phase the two firewalls will negotiate about the IPsec security parameters that will be used to protect the traffic within the tunnel. In short, this is what happens in phase 2: Negotiate IPsec security parameters through the secure tunnel from phase 1. Establish IPsec security associations. Periodically renegotiates IPsec security associations for security.
Topics
Community Discussion
No community discussion yet for this question.
