nerdexam
Cisco

350-701 · Question #831

A network engineer must establish a site-to-site VPN between two Cisco routers using IPsec. The engineer creates an access control list to permit the traffic, configures phase 1 and phase 2 of…

The correct answer is A. Configure the routers to exclude traffic from NAT. In a site-to-site IPsec VPN configuration, the traffic to be encrypted and sent over the VPN tunnel must bypass Network Address Translation (NAT). If NAT is not excluded, the private IP addresses will be translated, and the IPsec VPN will not function correctly, as the…

Submitted by noor.lb· Mar 30, 2026Network Security

Question

A network engineer must establish a site-to-site VPN between two Cisco routers using IPsec. The engineer creates an access control list to permit the traffic, configures phase 1 and phase 2 of IPsec, and applies the crypto map from the routers to the public interface. Which action completes the configuration?

Options

  • AConfigure the routers to exclude traffic from NAT.
  • BPing one of the routers to verify network connectivity.
  • CEstablish the IPsec VPN tunnel.
  • DCreate an extended access control list on one of the routers to allow inbound traffic.

How the community answered

(33 responses)
  • A
    70% (23)
  • B
    18% (6)
  • C
    9% (3)
  • D
    3% (1)

Explanation

In a site-to-site IPsec VPN configuration, the traffic to be encrypted and sent over the VPN tunnel must bypass Network Address Translation (NAT). If NAT is not excluded, the private IP addresses will be translated, and the IPsec VPN will not function correctly, as the integrity checks will fail due to address mismatch.

Topics

#IPsec VPN#NAT exemption#Site-to-site VPN#Cisco VPN config

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice