nerdexam
Cisco

300-730 · Question #158

Refer to the exhibit. An engineer has configured two new VPN tunnels to 172.18.1.1 and 172.19.1.1. However, communication between 10.1.0.10 and 10.1.11.10 does not function. Which action should be…

When site-to-site VPN tunnels are established but traffic between hosts fails, the network objects defining interesting traffic in the crypto map must correctly match the actual source and destination subnets.

Troubleshooting Using ASDM and CLI

Question

Refer to the exhibit. An engineer has configured two new VPN tunnels to 172.18.1.1 and 172.19.1.1. However, communication between 10.1.0.10 and 10.1.11.10 does not function. Which action should be taken to resolve this issue?

Options

  • ARemove and reapply the crypto map to the interface.
  • BInsert routes for the 10.1.9.0/24 and 10.1.10.0/24 subnets.
  • CModify the transform set to use transport mode.
  • DAdjust the network objects to match the appropriate subnets.

Why each option

When site-to-site VPN tunnels are established but traffic between hosts fails, the network objects defining interesting traffic in the crypto map must correctly match the actual source and destination subnets.

ARemove and reapply the crypto map to the interface.

Removing and reapplying the crypto map is a workaround for a stuck or incorrectly bound crypto engine state, not a fix for misconfigured interesting traffic definitions.

BInsert routes for the 10.1.9.0/24 and 10.1.10.0/24 subnets.

Inserting routes for 10.1.9.0/24 and 10.1.10.0/24 addresses a routing gap for different subnets unrelated to the 10.1.0.10 to 10.1.11.10 communication path.

CModify the transform set to use transport mode.

Transport mode is used for host-to-host IPsec sessions, not site-to-site gateway tunnels, and switching to it would break rather than restore the tunnel.

DAdjust the network objects to match the appropriate subnets.

Concept tested: Crypto map network object configuration for site-to-site VPN

Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119501-configure-asa-00.html

Topics

#crypto map#network objects#ACL#site-to-site VPN

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice