nerdexam
Cisco

210-260 · Question #66

Refer to the exhibit. While troubleshooting site-to-site VPN, you issued the show crypto ipsec sa command. What does the given output show?

The correct answer is B. IPSec Phase 2 is established between 10.1.1.1 and 10.1.1.5. Once the secure tunnel from phase 1 has been established, we will start phase 2. In this phase the two firewalls will negotiate about the IPsec security parameters that will be used to protect the traffic within the tunnel. In short, this is what happens in phase 2: Negotiate…

VPN

Question

Refer to the exhibit. While troubleshooting site-to-site VPN, you issued the show crypto ipsec sa command. What does the given output show?

Exhibit

210-260 question #66 exhibit

Options

  • AISAKMP security associations are established between 10.1.1.5 and 10.1.1.1
  • BIPSec Phase 2 is established between 10.1.1.1 and 10.1.1.5
  • CIKE version 2 security associations are established between 10.1.1.1 and 10.1.1.5
  • DIPSec Phase 2 is down due to a mismatch between encrypted and decrypted packets

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    79% (23)
  • C
    14% (4)
  • D
    3% (1)

Explanation

Once the secure tunnel from phase 1 has been established, we will start phase 2. In this phase the two firewalls will negotiate about the IPsec security parameters that will be used to protect the traffic within the tunnel. In short, this is what happens in phase 2: Negotiate IPsec security parameters through the secure tunnel from phase 1. Establish IPsec security associations. Periodically renegotiates IPsec security associations for security.

Topics

#show crypto ipsec sa#IPSec Phase 2#site-to-site VPN#SA troubleshooting

Community Discussion

No community discussion yet for this question.

Full 210-260 Practice