nerdexam
Palo_Alto_Networks

PCNSE7 · Question #130

Site-A and Site-B need to use IKEv2 to establish a VPN connection. Site-A connects directly to the internet using a public IP address. Site-B uses a private IP address behind an ISP router to…

The correct answer is C. Enable on Site-A and Site-B. NAT traversal (NAT-T) must be enabled on both gateways if you have NAT occurring on a device that sits between the two gateways. A gateway can see only the public (globally routable) IP address of the NAT device.

Configure and Deploy

Question

Site-A and Site-B need to use IKEv2 to establish a VPN connection. Site-A connects directly to the internet using a public IP address. Site-B uses a private IP address behind an ISP router to connect to the internet. How should NAT Traversal be implemented for the VPN connection to be established between Site-A and Site-B?

Options

  • AEnable on Site-A only
  • BEnable on Site-B only with Passive Mode
  • CEnable on Site-A and Site-B
  • DEnable on Site-B only

How the community answered

(24 responses)
  • A
    8% (2)
  • B
    17% (4)
  • C
    71% (17)
  • D
    4% (1)

Explanation

NAT traversal (NAT-T) must be enabled on both gateways if you have NAT occurring on a device that sits between the two gateways. A gateway can see only the public (globally routable) IP address of the NAT device.

Topics

#IKEv2#NAT Traversal#IPsec VPN#NAT behind router

Community Discussion

No community discussion yet for this question.

Full PCNSE7 Practice