PCNSE · Question #789
What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?
The correct answer is A. Phase 2 SAs are synchronized over HA2 links. In an Active/Passive HA pair, only Phase 2 (IPsec) Security Associations are synchronized, and they are synchronized over the HA2 data link. Phase 1 (IKE) SAs are not synchronized between HA peers because IKE negotiations are lightweight and can be quickly re-established after…
Question
What happens when an A/P firewall pair synchronizes IPsec tunnel security associations (SAs)?
Options
- APhase 2 SAs are synchronized over HA2 links.
- BPhase 1 and Phase 2 SAs are synchronized over HA2 links.
- CPhase 1 SAs are synchronized over HA1 links.
- DPhase 1 and Phase 2 SAs are synchronized over HA3 links.
How the community answered
(47 responses)- A94% (44)
- C4% (2)
- D2% (1)
Explanation
In an Active/Passive HA pair, only Phase 2 (IPsec) Security Associations are synchronized, and they are synchronized over the HA2 data link. Phase 1 (IKE) SAs are not synchronized between HA peers because IKE negotiations are lightweight and can be quickly re-established after a failover. Synchronizing Phase 2 SAs ensures that existing encrypted tunnels remain active without requiring full IKE and IPsec renegotiation after a failover event, minimizing traffic disruption.
Topics
Community Discussion
No community discussion yet for this question.