300-710 · Question #271
A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 45
The correct answer is C. Modify the NAT policy to use the interface PAT.. In a site-to-site IPsec VPN configuration where one router is behind a Cisco FTD (Firepower Threat Defense) firewall, proper NAT traversal is critical. Even if you've allowed UDP 500 (ISAKMP), UDP 4500 (NAT-T), and ESP (IP protocol 50) in the access policy, NAT can still break th
Question
A network administrator is configuring a site-to-site IPsec VPN to a router sitting behind a Cisco FTD. The administrator has configured an access policy to allow traffic to this device on UDP 500, 4500, and ESP VPN traffic is not working. Which action resolves this issue?
Options
- ASet the allow action in the access policy to trust.
- BEnable IPsec inspection on the access policy.
- CModify the NAT policy to use the interface PAT.
- DChange the access policy to allow all ports.
How the community answered
(44 responses)- A2% (1)
- B14% (6)
- C77% (34)
- D7% (3)
Explanation
In a site-to-site IPsec VPN configuration where one router is behind a Cisco FTD (Firepower Threat Defense) firewall, proper NAT traversal is critical. Even if you've allowed UDP 500 (ISAKMP), UDP 4500 (NAT-T), and ESP (IP protocol 50) in the access policy, NAT can still break the VPN unless handled properly.
Topics
Community Discussion
No community discussion yet for this question.