An engineer must deploy a high-availability pair that includes two Cisco Secure Firewall Threat Defense devices. The deployment must provide a mechanism that protects synchronization traffic between the members. Which action must the engineer take?
A.
Configure an SSL VPN tunnel between the units.
B.
Select the Key Generation method for IPsec encryption.
C.
Encrypt the synchronization traffic with SSL.
D.
Clear the commit queue when synchronization begins.
Cisco Secure Firewall Threat Defense supports IPsec encryption between the failover links of a high-availability pair. During HA configuration, the engineer enables encryption and selects the appropriate Key Generation method for IPsec. This protects failover and stateful synchronization data exchanged between the active and standby units. An SSL remote-access VPN is designed for user-to-network connectivity and is not used to protect an internal HA link. SSL is also not the documented encryption mechanism for Threat Defense failover synchronization. Clearing a commit queue does not encrypt or otherwise protect synchronized state information. Cisco’s HA configuration procedure explicitly instructs administrators to enable the encryption option and choose the Key Generation method for IPsec encryption between the failover links. Therefore, option B directly implements the required synchronization-protection mechanism. Cisco Secure Firewall high-availability configuration
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit