H12-725_V4.0 · Question #311
In a point-to-multipoint scenario, and the headquarters address is fixed and the branch address is not fixed, it is recommended to use IPSec policy template method to establish VPN.
The correct answer is A. True. Option A is correct because IPSec policy templates (also called "policy templates" or "responder-mode templates") are specifically designed for point-to-multipoint scenarios where the central site (headquarters) has a static IP but remote branches have dynamic IPs. The template…
Question
In a point-to-multipoint scenario, and the headquarters address is fixed and the branch address is not fixed, it is recommended to use IPSec policy template method to establish VPN.
Options
- ATrue
- BFalse
How the community answered
(59 responses)- A73% (43)
- B27% (16)
Explanation
Option A is correct because IPSec policy templates (also called "policy templates" or "responder-mode templates") are specifically designed for point-to-multipoint scenarios where the central site (headquarters) has a static IP but remote branches have dynamic IPs. The template allows the headquarters to accept incoming VPN connections from any branch without pre-configuring a specific peer IP address for each one.
Option B is wrong because rejecting this statement would imply a standard IPSec policy (with a fixed peer IP on both ends) is sufficient - but that breaks down the moment branch offices use DHCP or PPPoE addresses that change, since standard policies require knowing the peer's address in advance.
Memory tip: Think of a "template" like a hotel check-in form - headquarters keeps the same address (the hotel), while branches (guests) can come from anywhere with different IDs. The template handles whoever shows up, rather than reserving a room for a specific known guest.
Topics
Community Discussion
No community discussion yet for this question.