nerdexam
Palo_Alto_Networks

NGFW-ENGINEER · Question #99

A network architect is planning the deployment of a new IPSec VPN tunnel to connect a local data center to a cloud environment. The plan must include all necessary Security policy configurations for…

The correct answer is B. A policy must explicitly permit only the IKE application between the external-facing zone and local C. A pair of policies is required to control the flow of data traffic into and out of the security zone. IKE negotiation traffic must be explicitly permitted between the external-facing zone and the local zone so the tunnel can be established, and separate Security policy rules are required to control the actual user/data traffic entering and leaving the zone assigned to the…

VPN Implementation and Security Policy Management

Question

A network architect is planning the deployment of a new IPSec VPN tunnel to connect a local data center to a cloud environment. The plan must include all necessary Security policy configurations for both tunnel negotiation and data transit. Which two Security policy requirements must be included in the implementation plan? (Choose two.)

Options

  • AA policy must explicitly permit the IPSec container application between the external-facing zone
  • BA policy must explicitly permit only the IKE application between the external-facing zone and local
  • CA pair of policies is required to control the flow of data traffic into and out of the security zone
  • DThe default interzone-default security policy is sufficient to allow the tunnel negotiation traffic

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    76% (29)
  • D
    16% (6)

Explanation

IKE negotiation traffic must be explicitly permitted between the external-facing zone and the local zone so the tunnel can be established, and separate Security policy rules are required to control the actual user/data traffic entering and leaving the zone assigned to the tunnel interface to enforce what can traverse the VPN.

Topics

#IPSec VPN#Security Policies#IKE#Data Transit

Community Discussion

No community discussion yet for this question.

Full NGFW-ENGINEER Practice