NGFW-ENGINEER · Question #120
An administrator is troubleshooting a newly configured site-to-site VPN between a PAN-OS firewall and a third-party policy-based VPN gateway. The tunnel allows traffic between the first pair of…
The correct answer is C. The new local and remote subnets are missing from the Proxy ID configuration. With a policy-based VPN, Phase 2 traffic selectors must explicitly include each permitted local and remote subnet pair. If the new subnet pair was added in routing and policy but not added to the Proxy ID configuration, the peer will not negotiate selectors for that traffic, so…
Question
An administrator is troubleshooting a newly configured site-to-site VPN between a PAN-OS firewall and a third-party policy-based VPN gateway. The tunnel allows traffic between the first pair of configured subnets, but traffic to a newly added remote subnet is failing. The administrator has confirmed that routing and Security policies are correct. What is the most likely cause of this issue?
Options
- AA static route for the new subnet pointing to the tunnel interface is missing.
- BThe Security policy for the new subnet must be placed above the existing VPN policy.
- CThe new local and remote subnets are missing from the Proxy ID configuration.
- DThe tunnel's maximum transmission unit (MTU) size must be increased to accommodate the new
How the community answered
(61 responses)- A5% (3)
- B8% (5)
- C72% (44)
- D15% (9)
Explanation
With a policy-based VPN, Phase 2 traffic selectors must explicitly include each permitted local and remote subnet pair. If the new subnet pair was added in routing and policy but not added to the Proxy ID configuration, the peer will not negotiate selectors for that traffic, so the new subnet traffic fails while the original subnet continues to work.
Topics
Community Discussion
No community discussion yet for this question.