nerdexam
Palo_Alto_NetworksPalo_Alto_Networks

PCNSE · Question #627

PCNSE Question #627: Real Exam Question with Answer & Explanation

Sign in or unlock PCNSE to reveal the answer and full explanation for question #627. The question stem and answer options stay visible for context.

Submitted by obi.ng· Apr 18, 2026Configuration Troubleshooting

Question

An engineer troubleshooting a site-to-site VPN finds a Security policy dropping the peer's IKE traffic at the edge firewall. Both VPN peers are behind a NAT, and NAT-T is enabled. How can the engineer remediate this issue?

Options

  • AAdd a Security policy to allow UDP/500.
  • BAdd a Security policy to allow the IKE application.
  • CAdd a Security policy to allow the IPSec application.
  • DAdd a Security policy to allow UDP/4501.

Unlock PCNSE to see the answer

You've previewed enough free PCNSE questions. Unlock PCNSE for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#VPN Troubleshooting#IKE#Security Policy#NAT-T
Full PCNSE PracticeBrowse All PCNSE Questions