nerdexam
Juniper

JN0-635 · Question #67

The IPsec VPN on your SRX Series device establishes both the Phase 1 and Phase 2 security associations. Users are able to pass traffic through the VPN. During peak VPN usage times, users complain…

The correct answer is A. Lower the MTU size on the interface to reduce the likelihood of packet fragmentation. C. Lower the MSS setting in the security flow stanza for IPsec VPNs. See the full explanation below for the reasoning.

Question

The IPsec VPN on your SRX Series device establishes both the Phase 1 and Phase 2 security associations. Users are able to pass traffic through the VPN. During peak VPN usage times, users complain about decreased performance. Network connections outside of the VPN are not seriously impacted. Which two actions will resolve the problem? (Choose two.)

Options

  • ALower the MTU size on the interface to reduce the likelihood of packet fragmentation.
  • BVerify that NAT-T is not disabled in the properties of the phase 1 gateway.
  • CLower the MSS setting in the security flow stanza for IPsec VPNs.
  • DVerify that the PKI certificate used to establish the VPN is being properly verified using either the

How the community answered

(60 responses)
  • A
    73% (44)
  • B
    18% (11)
  • D
    8% (5)

Community Discussion

No community discussion yet for this question.

Full JN0-635 Practice