nerdexam
Juniper

JN0-696 · Question #25

Two SRX Series devices are having problems establishing an IPsec VPN session. One of the devices has a firewall filter applied to its gateway interface that rejects UDP traffic. What would resolve…

The correct answer is D. Edit the firewall filter to allow UDP port 500. UDP port 500 is used by IKE.

Troubleshooting IPsec

Question

Two SRX Series devices are having problems establishing an IPsec VPN session. One of the devices has a firewall filter applied to its gateway interface that rejects UDP traffic. What would resolve the problem?

Options

  • ADisable the IKE Phase 1 part of the session establishment.
  • BDisable the IKE Phase 2 part of the session establishment.
  • CChange the configuration so that session establishment uses TCP.
  • DEdit the firewall filter to allow UDP port 500.

How the community answered

(24 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    4% (1)
  • D
    83% (20)

Explanation

UDP port 500 is used by IKE.

Topics

#IKE#UDP port 500#firewall filter blocking#IPsec VPN

Community Discussion

No community discussion yet for this question.

Full JN0-696 Practice