You are installing a brand-new, site-to-site VPN tunnel and notice that it is not working correctly.
When connecting to the corporate router and issuing a show crypto ipsec sa command, you notice
that for this particular SA that packets are being encrypted but not decrypted. What are two
potential reasons for this problem? (Choose two.)
A.
XAUTH needs to be enabled.
B.
Inbound and outbound IP 50 packets are being filtered at the remote site.
C.
The transform-set needs to be set to transport mode.
D.
The access-list attached to the crypto map at the remote site is incorrect.
E.
The remote site is failing Diffie-Hellman Phase I negotiation.
F.
The NAT exception on the corporate side is filtering the return packets.