nerdexam
Juniper

JN0-633 · Question #62

You are troubleshooting an IPsec session and see the following IPsec security associations: ID Gateway Port Algorithm SPI Life:sec/kb Mon vsys < 192.168.224.1 500 ESP:aes-256/sha1 d6393645 26/ unlim…

The correct answer is C. The lifetime of the Phase 2 negotiation is close to expiration. D. Both peers have establish-tunnels immediately configured. ipsec-security-associations.html

VPNs (IPsec, SSL)

Question

You are troubleshooting an IPsec session and see the following IPsec security associations:

ID Gateway Port Algorithm SPI Life:sec/kb Mon vsys < 192.168.224.1 500 ESP:aes-256/sha1 d6393645 26/ unlim - 0 > 192.168.224.1 500 ESP:aes-256/sha1 153ec235 26/ unlim - 0 < 192.168.224.1 500 ESP:aes-256/sha1 f9a2db9a 3011/ unlim - 0 > 192.168.224.1 500 ESP:aes-256/sha1 153ec236 3011/ unlim - 0 What are two reasons for this behavior? (Choose two.)

Options

  • ABoth peers are trying to establish IKE Phase 1 but are not successful.
  • BBoth peers have established SAs with one another, resulting in two IPsec tunnels.
  • CThe lifetime of the Phase 2 negotiation is close to expiration.
  • DBoth peers have establish-tunnels immediately configured.

How the community answered

(27 responses)
  • A
    11% (3)
  • B
    4% (1)
  • C
    85% (23)

Explanation

ipsec-security-associations.html

Topics

#IPsec SA duplication#Phase 2 lifetime#establish-tunnels immediately#duplicate tunnels

Community Discussion

No community discussion yet for this question.

Full JN0-633 Practice