nerdexam
Cisco

300-440 · Question #15

Refer to the exhibit. While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the security association…

The correct answer is B. identity mismatch. An active ISAKMP SA with no passing traffic indicates a proxy-ID (identity) mismatch-the local/remote traffic selectors (subnets) don't match between the Cisco router and AWS, so data- plane SAs aren't built for the interesting traffic.

Operation

Question

Refer to the exhibit. While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the security association status is active, but no traffic flows between the devices. What is the problem?

Exhibit

300-440 question #15 exhibit

Options

  • Awrong ISAKMP policy
  • Bidentity mismatch
  • Cwrong encryption
  • DIKE version mismatch

How the community answered

(42 responses)
  • A
    10% (4)
  • B
    48% (20)
  • C
    26% (11)
  • D
    17% (7)

Explanation

An active ISAKMP SA with no passing traffic indicates a proxy-ID (identity) mismatch-the local/remote traffic selectors (subnets) don't match between the Cisco router and AWS, so data- plane SAs aren't built for the interesting traffic.

Topics

#IPsec troubleshooting#identity mismatch#security association#IKE

Community Discussion

No community discussion yet for this question.

Full 300-440 Practice