Referring to partial IOS router configuration shown in the exhibit, which statement is true?
A.
Traffic from subnet 172.16.4. 0/24 to the 172.16.3.0/24 subnet will be protected by IPSec and will go through NAT
B.
All traffic from subnet 172.16.4.0/24 to the 172.16.3.0/24 subnet will go through NAT
C.
ACL 104 is the crypto ACL defining traffic that should be protected by IPSec
D.
Traffic from subnet 172.16.4.0/24 to any destinations will be protected by IPSec and will bypass NAT
E.
All IPSec protected traffic will bypass NAT
Explanation:
Traffic between the 2 networks will go encrypted as per ACL crypto 103 and will not fall in the NAT as per the deny in ACL 104 unless if not going to that subnet..
Ans is E
because the interesting traffic of IPSEC has been denied in ACL 104 and then called it to the Route-map for Nat, Route-map is in permit state so the interested traffic of IPSEC will now not face the NAT.
so ANS A is wrong.
Yes, E is the correct answer even though the permitted traffic will fail in an actual implementation.