H12-725_V4.0 · Question #189
Which of the following descriptions of IPSec security policies in policy template mode are correct? (Multiple choice)
The correct answer is A. In the policy template configuration, referencing the IPSec security proposal and IKE peer is a B. If the peer uses PPPoE dial-up to obtain an IP address, you can use this method to establish a D. The IPSec security policy using policy templates can simplify multiple IPSec. IPSec policy template mode is designed for scenarios where a responder (hub side) must accept connections from peers whose IP addresses are unknown or dynamically assigned. A is correct because in policy template configuration, referencing the IPSec security proposal and IKE…
Question
Which of the following descriptions of IPSec security policies in policy template mode are correct? (Multiple choice)
Options
- AIn the policy template configuration, referencing the IPSec security proposal and IKE peer is a
- BIf the peer uses PPPoE dial-up to obtain an IP address, you can use this method to establish a
- CBoth ends of the IPSec tunnel can be configured with IPSec in policy template mode.
- DThe IPSec security policy using policy templates can simplify multiple IPSec
How the community answered
(52 responses)- A73% (38)
- C27% (14)
Explanation
IPSec policy template mode is designed for scenarios where a responder (hub side) must accept connections from peers whose IP addresses are unknown or dynamically assigned.
A is correct because in policy template configuration, referencing the IPSec security proposal and IKE peer is optional - the template is intentionally flexible to accept peers whose parameters aren't fully known in advance.
B is correct because policy template mode was specifically built for dynamic-IP scenarios like PPPoE dial-up, where the initiating peer cannot have a static IP configured on the responder side ahead of time.
D is correct because a single policy template can handle multiple remote peers simultaneously, eliminating the need to create individual IPSec security policies for each remote site.
C is wrong - this is the key distractor. Policy template mode is asymmetric by design: only the responder (the side with a fixed, known IP) uses the template. The initiator must use a standard IPSec security policy. If both ends used templates, neither could reliably initiate the tunnel.
Memory tip: Think of a policy template as a "reception desk" - only one side (the fixed-IP server) sits at the desk waiting to accept unknown visitors. The visitors (dynamic-IP peers) still need their own "ID badge" (regular security policy) to initiate contact. One desk, many visitors - never two desks facing each other.
Topics
Community Discussion
No community discussion yet for this question.