nerdexam
Cisco

300-820 · Question #99

Refer to the exhibit showing logs from the Expressway-C, a copy of the Expressway-E certificate, and the UC traversal zone configuration for the Expressway-C. An office administrator is deploying…

The correct answer is C. In the UC Traversal Zone on the Expressway-C, the peer address is set to the IP of the. TLS authentication requires that the hostname used to connect to a peer matches what is listed in that peer's certificate (Common Name or Subject Alternative Name). When the UC Traversal Zone on Expressway-C is configured with the IP address of Expressway-E (rather than its…

Mobile and Remote Access

Question

Refer to the exhibit showing logs from the Expressway-C, a copy of the Expressway-E certificate, and the UC traversal zone configuration for the Expressway-C. An office administrator is deploying mobile and remote access and sees an issue with the UC traversal zone. The zone is showing "TLS negotiation failure". What is causing this issue?

Exhibit

300-820 question #99 exhibit

Options

  • AThe Expressway-E certificate includes the Expressway-C FQDN as a SAN entry
  • BThe Expressway-C is missing the FQDN of Cisco UCM in the Common Name of its certificate
  • CIn the UC Traversal Zone on the Expressway-C, the peer address is set to the IP of the
  • DThe Expressway-E does not have the FQDN of Cisco UCM listed as a SAN in its certificate

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • C
    81% (21)
  • D
    12% (3)

Explanation

TLS authentication requires that the hostname used to connect to a peer matches what is listed in that peer's certificate (Common Name or Subject Alternative Name). When the UC Traversal Zone on Expressway-C is configured with the IP address of Expressway-E (rather than its FQDN), TLS validation fails because the Expressway-E certificate contains its FQDN (e.g., expressway-e.company.com) - not an IP address. The TLS handshake checks the peer address against the certificate and finds no match, causing the 'TLS negotiation failure'. The fix is to set the peer address in the UC Traversal Zone to the FQDN of Expressway-E so it matches what is in the certificate.

Topics

#Mobile and Remote Access#Cisco Expressway#Traversal Zone#TLS Negotiation

Community Discussion

No community discussion yet for this question.

Full 300-820 Practice