PCNSE · Question #811
In which two scenarios would it be necessary to use Proxy IDs when configuring site-to-site VPN Tunnels? (Choose two.)
The correct answer is A. Firewalls which support policy-based VPNs. B. The remote device is a non-Palo Alto Networks firewall. The remote device is a non-Palo Alto Networks firewall: When configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a non-Palo Alto device, Proxy IDs may be required to define which IP ranges should be used for traffic between the two endpoints. Proxy…
Question
In which two scenarios would it be necessary to use Proxy IDs when configuring site-to-site VPN Tunnels? (Choose two.)
Options
- AFirewalls which support policy-based VPNs.
- BThe remote device is a non-Palo Alto Networks firewall.
- CFirewalls which support route-based VPNs.
- DThe remote device is a Palo Alto Networks firewall.
How the community answered
(31 responses)- A84% (26)
- C6% (2)
- D10% (3)
Explanation
The remote device is a non-Palo Alto Networks firewall: When configuring a site-to-site VPN tunnel between a Palo Alto Networks firewall and a non-Palo Alto device, Proxy IDs may be required to define which IP ranges should be used for traffic between the two endpoints. Proxy IDs are used in scenarios where the non-Palo Alto firewall does not automatically detect and manage the traffic selectors, so the administrator must manually specify the traffic selectors using Firewalls which support policy-based VPNs: In policy-based VPNs, the firewall uses specific policies to define the traffic selectors, and these must be explicitly defined in both devices for the VPN to be correctly established. Proxy IDs are used to define these traffic selectors, indicating which IP addresses and subnets should be encrypted over the VPN.
Topics
Community Discussion
No community discussion yet for this question.