Cisco
300-440 · Question #15
Refer to the exhibit. While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the security association…
The correct answer is B. identity mismatch. An active ISAKMP SA with no passing traffic indicates a proxy-ID (identity) mismatch-the local/remote traffic selectors (subnets) don't match between the Cisco router and AWS, so data- plane SAs aren't built for the interesting traffic.
Operation
Question
Refer to the exhibit. While troubleshooting an IPsec connection between a Cisco WAN edge router and an Amazon Web Services (AWS) endpoint, a network engineer observes that the security association status is active, but no traffic flows between the devices. What is the problem?
Exhibit
Options
- Awrong ISAKMP policy
- Bidentity mismatch
- Cwrong encryption
- DIKE version mismatch
How the community answered
(42 responses)- A10% (4)
- B48% (20)
- C26% (11)
- D17% (7)
Explanation
An active ISAKMP SA with no passing traffic indicates a proxy-ID (identity) mismatch-the local/remote traffic selectors (subnets) don't match between the Cisco router and AWS, so data- plane SAs aren't built for the interesting traffic.
Topics
#IPsec troubleshooting#identity mismatch#security association#IKE
Community Discussion
No community discussion yet for this question.
