nerdexam
Cisco

300-440 · Question #10

Refer to the exhibit. An engineer successfully brings up the site-to-site VPN tunnel between the remote office and the AWS virtual private gateway, and the site-to-site routing works correctly…

The correct answer is B. Check the security group rules for the host VPC. C. Check the IPsec SA counters. The end-to-end ping between the office user PC and the AWS EC2 instance is not working because either the security group rules for the host VPC are blocking the ICMP traffic or the IPsec SA counters are showing errors or drops. To diagnose the loss of connectivity, the engineer…

Operation

Question

Refer to the exhibit. An engineer successfully brings up the site-to-site VPN tunnel between the remote office and the AWS virtual private gateway, and the site-to-site routing works correctly. However, the end-to-end ping between the office user PC and the AWS EC2 instance is not working. Which two actions diagnose the loss of connectivity? (Choose two.)

Exhibit

300-440 question #10 exhibit

Options

  • ACheck the network security group rules on the host VNET.
  • BCheck the security group rules for the host VPC.
  • CCheck the IPsec SA counters.
  • DOn the Cisco VPN router, configure the IPsec SA to allow ping packets.
  • EOn the AWS private virtual gateway, configure the IPsec SA to allow ping packets.

How the community answered

(53 responses)
  • A
    13% (7)
  • B
    58% (31)
  • D
    25% (13)
  • E
    4% (2)

Explanation

The end-to-end ping between the office user PC and the AWS EC2 instance is not working because either the security group rules for the host VPC are blocking the ICMP traffic or the IPsec SA counters are showing errors or drops. To diagnose the loss of connectivity, the engineer should check both the security group rules and the IPsec SA counters. The network security group rules on the host VNET are not relevant because they apply to Azure, not AWS. The IPsec SA configuration on the Cisco VPN router and the AWS private virtual gateway are not likely to be the cause of the problem because the site-to-site VPN tunnel is already up and the site-to-site routing works correctly.

Topics

#VPN troubleshooting#AWS security groups#IPsec SA#end-to-end connectivity

Community Discussion

No community discussion yet for this question.

Full 300-440 Practice