300-730 · Question #158
Refer to the exhibit. An engineer has configured two new VPN tunnels to 172.18.1.1 and 172.19.1.1. However, communication between 10.1.0.10 and 10.1.11.10 does not function. Which action should be…
When site-to-site VPN tunnels are established but traffic between hosts fails, the network objects defining interesting traffic in the crypto map must correctly match the actual source and destination subnets.
Question
Options
- ARemove and reapply the crypto map to the interface.
- BInsert routes for the 10.1.9.0/24 and 10.1.10.0/24 subnets.
- CModify the transform set to use transport mode.
- DAdjust the network objects to match the appropriate subnets.
Why each option
When site-to-site VPN tunnels are established but traffic between hosts fails, the network objects defining interesting traffic in the crypto map must correctly match the actual source and destination subnets.
Removing and reapplying the crypto map is a workaround for a stuck or incorrectly bound crypto engine state, not a fix for misconfigured interesting traffic definitions.
Inserting routes for 10.1.9.0/24 and 10.1.10.0/24 addresses a routing gap for different subnets unrelated to the 10.1.0.10 to 10.1.11.10 communication path.
Transport mode is used for host-to-host IPsec sessions, not site-to-site gateway tunnels, and switching to it would break rather than restore the tunnel.
Concept tested: Crypto map network object configuration for site-to-site VPN
Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/119501-configure-asa-00.html
Topics
Community Discussion
No community discussion yet for this question.