nerdexam
Juniper

JN0-1330 · Question #59

An auditor reviewed your company's firewall configurations and is requiring that IPsec VPN connections must not expose IKE identities during IKE negotiations. Which two methods satisfy this…

The correct answer is A. Use main mode for the IKE policy. Explanation/Reference: Main Mode and Aggressive Mode IKE phase 1 negotiations are used to establish IKE SAs. These SAs protect the IKE phase 2 negotiations. IKE uses one of two modes for phase 1 negotiations: main mode or aggressive mode. The choice of main or aggressive mode…

Secure Access and VPN Design

Question

An auditor reviewed your company’s firewall configurations and is requiring that IPsec VPN connections must not expose IKE identities during IKE negotiations. Which two methods satisfy this requirement? (Choose two.)

Options

  • AUse main mode for the IKE policy.
  • BUse aggressive mode for the IKE policy.
  • CUse IKEv2 instead of IKEv1.
  • DConfigure GRE over IPsec.

How the community answered

(26 responses)
  • A
    77% (20)
  • B
    4% (1)
  • C
    8% (2)
  • D
    12% (3)

Explanation

Explanation/Reference: Main Mode and Aggressive Mode IKE phase 1 negotiations are used to establish IKE SAs. These SAs protect the IKE phase 2 negotiations. IKE uses one of two modes for phase 1 negotiations: main mode or aggressive mode. The choice of main or aggressive mode is a matter of tradeoffs. Some of the characteristics of the two modes are: - Protects the identities of the peers during negotiations and is therefore more secure. - Enables greater proposal flexibility than aggressive mode. - Is more time consuming than aggressive mode because more messages are exchanged between peers. (Six messages are exchanged in main mode.) - Exposes identities of the peers to eavesdropping, making it less secure than main mode. - Is faster than main mode because fewer messages are exchanged between peers. (Three messages are exchanged in aggressive mode.) - Enables support for fully qualified domain names (FQDNs) when the router uses preshared keys. swconfig-ip-services/id-79352.html

Topics

#IKE main mode#aggressive mode#identity protection#IKEv2

Community Discussion

No community discussion yet for this question.

Full JN0-1330 Practice