nerdexam
HP

HPE7-A02 · Question #31

A company is implementing a client-to-site VPN based on tunnel-mode IPsec. Which devices are responsible for the IPsec encapsulation?

The correct answer is C. The remote clients and a gateway at the main site. In a client-to-site VPN based on tunnel-mode IPsec, the remote clients and a gateway at the main site are responsible for the IPsec encapsulation. The remote clients initiate the VPN connection and encapsulate their traffic in IPsec, which is then decapsulated by the gateway at…

Designing and Planning Network Security Deployments

Question

A company is implementing a client-to-site VPN based on tunnel-mode IPsec. Which devices are responsible for the IPsec encapsulation?

Options

  • AGateways at the remote clients' locations and devices accessed by the clients at the main site
  • BThe remote clients and devices accessed by the clients at the main site
  • CThe remote clients and a gateway at the main site
  • DGateways at the remote clients' locations and a gateway at the main site

How the community answered

(62 responses)
  • A
    2% (1)
  • B
    3% (2)
  • C
    90% (56)
  • D
    5% (3)

Explanation

In a client-to-site VPN based on tunnel-mode IPsec, the remote clients and a gateway at the main site are responsible for the IPsec encapsulation. The remote clients initiate the VPN connection and encapsulate their traffic in IPsec, which is then decapsulated by the gateway at the main site. 1. IPsec Encapsulation: The remote clients encapsulate their traffic using IPsec protocols before sending it over the internet to the main site. 2. Gateway Role: The gateway at the main site receives the encapsulated traffic, decapsulates it, and forwards it to the internal network. Similarly, traffic from the main site to the remote clients is encapsulated by the gateway and decapsulated by the clients. 3. Security: This setup ensures that data is securely transmitted between the remote clients and the main site, protecting it from eavesdropping and tampering.

Topics

#IPsec tunnel mode#client-to-site VPN#encapsulation#VPN architecture

Community Discussion

No community discussion yet for this question.

Full HPE7-A02 Practice