nerdexam
Juniper

JN0-632 · Question #59

Your company is bringing a remote office online and will use VPN connectivity for access to resources between offices. The remote SRX Series device has an IP address, which it obtained dynamically…

The correct answer is D. Use a fully qualified domain name (FQDN) as the IKE identity and configure IKE to use aggressive mode. See the full explanation below for the reasoning.

Question

Your company is bringing a remote office online and will use VPN connectivity for access to resources between offices. The remote SRX Series device has an IP address, which it obtained dynamically from a service provider. Which VPN technique can be used on your remote office SRX Series device?

Options

  • AConfigure the head office to allow promiscuous VPN connections and disable the use of IKE peer identities.
  • BUse the main-mode IKE exchange method in combination with a transport-mode tunnel.
  • CUse a certificate authority for IKE Phase 2 authentication.
  • DUse a fully qualified domain name (FQDN) as the IKE identity and configure IKE to use aggressive mode.

How the community answered

(64 responses)
  • A
    2% (1)
  • B
    9% (6)
  • C
    5% (3)
  • D
    84% (54)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice