nerdexam
Huawei

H12-725_V4.0 · Question #49

An enterprise has multiple branches. The exit IP address of the headquarters is fixed, but the exit IP addresses of the branches are random. An IPSec VPN needs to be established between the…

The correct answer is C. The headquarters adopts the policy template method, and the branches adopt the point-to-point. Option C is correct because the headquarters has a fixed IP, making it the natural responder - the policy template method lets HQ accept IPSec connections from any source IP without pre-configuring each branch's address. Since branch IPs are random (dynamic), the branches must…

VPN Technologies

Question

An enterprise has multiple branches. The exit IP address of the headquarters is fixed, but the exit IP addresses of the branches are random. An IPSec VPN needs to be established between the headquarters and branches. In order to reduce management and maintenance costs, which of the following is appropriate? How to configure IPSec VPN?

Options

  • AHeadquarters and branches adopt a point-to-point approach
  • BBoth the headquarters and branches adopt the strategic model approach
  • CThe headquarters adopts the policy template method, and the branches adopt the point-to-point
  • DThe headquarters and branches adopt IKE v2 method

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    16% (5)
  • C
    74% (23)
  • D
    3% (1)

Explanation

Option C is correct because the headquarters has a fixed IP, making it the natural responder - the policy template method lets HQ accept IPSec connections from any source IP without pre-configuring each branch's address. Since branch IPs are random (dynamic), the branches must be the initiators and can use point-to-point because they always know where to reach HQ's fixed IP. This combination eliminates the need to update HQ configuration each time a branch IP changes, directly reducing maintenance costs.

Why the distractors fail:

  • A - Point-to-point on both sides requires both endpoints to have known, fixed IPs; branches have dynamic IPs, so HQ can't hardcode them without constant reconfiguration.
  • B - Having branches also use the policy template is unnecessary and misconfigured - branches are initiators (they know the HQ IP), not responders; applying a template there adds complexity without benefit.
  • D - IKEv2 is a protocol version, not a topology solution; it doesn't inherently handle the dynamic-IP problem and doesn't reduce management costs on its own.

Memory tip: Think of HQ as a hotel with a fixed address - it uses an "open door policy" (policy template) to accept guests from any location, while the branches are travelers who always know the hotel's fixed address and dial in directly (point-to-point).

Topics

#IPSec VPN#Policy Templates#Dynamic IP Addressing#Hub-and-Spoke Topology

Community Discussion

No community discussion yet for this question.

Full H12-725_V4.0 Practice