PCNSE · Question #693
A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?
The correct answer is C. Select the appropriate DH Group under the IPSec Crypto profile. To resolve a VPN Phase 2 mismatch by enabling Perfect Forward Secrecy (PFS), the engineer must ensure a new Diffie-Hellman (DH) key exchange occurs during Phase 2. This is achieved by configuring the DH group within the IPSec Crypto profile, as PFS in Phase 2 is enabled by…
Question
A network engineer troubleshoots a VPN Phase 2 mismatch and decides that PFS (Perfect Forward Secrecy) needs to be enabled. What action should the engineer take?
Options
- AAdd an authentication algorithm in the IPSec Crypto profile.
- BEnable PFS under the IPSec Tunnel advanced options.
- CSelect the appropriate DH Group under the IPSec Crypto profile.
- DEnable PFS under the IKE gateway advanced options
How the community answered
(42 responses)- A5% (2)
- C88% (37)
- D7% (3)
Explanation
To resolve a VPN Phase 2 mismatch by enabling Perfect Forward Secrecy (PFS), the engineer must ensure a new Diffie-Hellman (DH) key exchange occurs during Phase 2. This is achieved by configuring the DH group within the IPSec Crypto profile, as PFS in Phase 2 is enabled by specifying a DH group.
Topics
Community Discussion
No community discussion yet for this question.