JN0-637 · Question #11
Your IPsec tunnel is configured with multiple security associations (SAs). Your SRX Series device supports the CoS-based IPsec VPNs with multiple IPsec SAs feature. You are asked to configure CoS…
The correct answer is B. A maximum of four forwarding classes can be configured for a VPN with the multi-sa forwarding- C. The local and remote gateways must have the forwarding classes defined in the same order. When configuring CoS-based IPsec VPNs with multiple IPsec SAs on Juniper SRX devices, the following rules apply: - Up to 4 forwarding classes can be mapped to different IPsec Security Associations using the multi-sa forwarding-classes statement. - The order of forwarding…
Question
Your IPsec tunnel is configured with multiple security associations (SAs). Your SRX Series device supports the CoS-based IPsec VPNs with multiple IPsec SAs feature. You are asked to configure CoS for this tunnel. Which two statements are true in this scenario? (Choose two.)
Options
- AThe local and remote gateways do not need the forwarding classes to be defined in the same
- BA maximum of four forwarding classes can be configured for a VPN with the multi-sa forwarding-
- CThe local and remote gateways must have the forwarding classes defined in the same order.
- DA maximum of eight forwarding classes can be configured for a VPN with the multi-sa forwarding-
How the community answered
(34 responses)- A6% (2)
- B74% (25)
- D21% (7)
Explanation
When configuring CoS-based IPsec VPNs with multiple IPsec SAs on Juniper SRX devices, the following rules apply: - Up to 4 forwarding classes can be mapped to different IPsec Security Associations using the multi-sa forwarding-classes statement. - The order of forwarding classes must match on both the local and remote gateways. Each SA corresponds to a class, so mismatches in order can result in traffic misclassification or drops.
Topics
Community Discussion
No community discussion yet for this question.