350-701 · Question #908
An engineer must configure a new site-to-site VPN connection using Cisco Secure Firewall Threat Defense as node A and Cisco ASA as node B. These configurations were performed already in Cisco Secure…
The correct answer is B. Configure NAT exemption. For a site-to-site VPN to function, traffic destined for the VPN tunnel must bypass NAT. Configuring NAT exemption ensures that internal networks exchanged between Cisco Secure Firewall Threat Defense and the ASA are not translated, allowing the IPsec tunnel to form and pass…
Question
An engineer must configure a new site-to-site VPN connection using Cisco Secure Firewall Threat Defense as node A and Cisco ASA as node B. These configurations were performed already in Cisco Secure Firewall Threat Defense:
- Configure IKE and IPsec parameters.
- Bypass access control.
- Create an access control policy.
Which action completes the configuration?
Options
- AEnable IKEv2 on the outside interface.
- BConfigure NAT exemption
- CAdd a VPN client profile.
- DCreate a tunnel group for the peer.
How the community answered
(44 responses)- A5% (2)
- B84% (37)
- C2% (1)
- D9% (4)
Explanation
For a site-to-site VPN to function, traffic destined for the VPN tunnel must bypass NAT. Configuring NAT exemption ensures that internal networks exchanged between Cisco Secure Firewall Threat Defense and the ASA are not translated, allowing the IPsec tunnel to form and pass traffic correctly. For a site-to-site VPN to function, traffic destined for the VPN tunnel must bypass NAT. Configuring NAT exemption ensures that internal networks exchanged between Cisco Secure Firewall Threat Defense and the ASA are not translated, allowing the IPsec tunnel to form and pass traffic correctly.
Topics
Community Discussion
No community discussion yet for this question.