What would resolve the problem?

Two SRX Series devices are having problems establishing an IPsec VPN session. One of the
devices has a firewall filter applied to its gateway interface that rejects UDP traffic.
What would resolve the problem?

Two SRX Series devices are having problems establishing an IPsec VPN session. One of the
devices has a firewall filter applied to its gateway interface that rejects UDP traffic.
What would resolve the problem?

A.
Disable the IKE Phase 1 part of the session establishment.

B.
Disable the IKE Phase 2 part of the session establishment.

C.
Change the configuration so that session establishment uses TCP.

D.
Edit the firewall filter to allow UDP port 500.

Explanation:



Leave a Reply 5

Your email address will not be published. Required fields are marked *


John

John

The right answer is D.

IKE uses UDP messages on port 500. You can’t disable Phase 1 or Phase 2 for establishing the tunnel, lol ๐Ÿ™‚
You can’t switch to TCP just like that either ๐Ÿ™‚

Junos

Junos

D is the correct Answer