nerdexam
CompTIA

220-1002 · Question #549

A user in a SOHO wants to allow Joe, a remote technician, to connect securely to the user's workstation. Joe informs the user that the VPN was successful, but he still cannot connect. Which of the…

The correct answer is B. Firewall. When a VPN connects successfully but a remote technician still cannot reach the workstation, the SOHO router firewall is the most likely cause because it may be blocking the specific remote access port or protocol independent of the VPN tunnel.

Networking

Question

A user in a SOHO wants to allow Joe, a remote technician, to connect securely to the user's workstation. Joe informs the user that the VPN was successful, but he still cannot connect. Which of the following settings in the SOHO router MOST likely need to be adjusted?

Options

  • AEncryption
  • BFirewall
  • CDHCP
  • DDNS
  • ENAT

How the community answered

(18 responses)
  • A
    11% (2)
  • B
    78% (14)
  • D
    6% (1)
  • E
    6% (1)

Why each option

When a VPN connects successfully but a remote technician still cannot reach the workstation, the SOHO router firewall is the most likely cause because it may be blocking the specific remote access port or protocol independent of the VPN tunnel.

AEncryption

Encryption settings govern the VPN tunnel itself, which is already confirmed working, so changing encryption parameters would not resolve a post-tunnel connectivity failure.

BFirewallCorrect

A SOHO router's built-in stateful firewall enforces its own inbound and outbound rules separately from any VPN tunnel that is established. The VPN only encrypts and encapsulates traffic - it does not override or bypass the router's firewall policies. Adjusting the firewall to permit the specific remote access protocol or destination port will resolve the connectivity block.

CDHCP

DHCP manages IP address lease assignments and does not control whether an established connection can reach a specific workstation behind the router.

DDNS

DNS handles hostname-to-IP resolution and, while a misconfiguration could cause name lookup failures, a VPN connecting successfully indicates the tunnel is functional and DNS is not the primary blocker.

ENAT

NAT is typically bypassed once a VPN tunnel is established, and since the VPN connection succeeded, NAT traversal is confirmed and is not the blocking factor.

Concept tested: SOHO router firewall blocking remote access over VPN

Source: https://learn.microsoft.com/en-us/windows/security/operating-system-security/network-security/windows-firewall/

Topics

#VPN#SOHO firewall#remote access#router configuration

Community Discussion

No community discussion yet for this question.

Full 220-1002 Practice