nerdexam
Cisco

300-710 · Question #271

A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 45

The correct answer is C. Modify the NAT policy to use the interface PAT.. In a site-to-site IPsec VPN configuration where one router is behind a Cisco FTD (Firepower Threat Defense) firewall, proper NAT traversal is critical. Even if you've allowed UDP 500 (ISAKMP), UDP 4500 (NAT-T), and ESP (IP protocol 50) in the access policy, NAT can still break th

Management and Troubleshooting

Question

A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?

Options

  • ASet the allow action in the access policy to trust.
  • BEnable IPsec inspection on the access policy.
  • CModify the NAT policy to use the interface PAT.
  • DChange the access policy to allow all ports.

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    14% (6)
  • C
    77% (34)
  • D
    7% (3)

Explanation

In a site-to-site IPsec VPN configuration where one router is behind a Cisco FTD (Firepower Threat Defense) firewall, proper NAT traversal is critical. Even if you've allowed UDP 500 (ISAKMP), UDP 4500 (NAT-T), and ESP (IP protocol 50) in the access policy, NAT can still break the VPN unless handled properly.

Topics

#IPsec VPN#Cisco FTD#NAT#Troubleshooting

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice