Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 141 Topic 15 Discussion

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 141 Topic 15 Discussion

350-701 Exam Topic 15 Question 141 Discussion:
Question #: 141
Topic #: 15

Refer to the exhibit.

350-701 Question 141

A site-to-site IKEv2 VPN between two Cisco Secure Firewall Threat Defense devices at a healthcare organization completes IKE Phase 1 successfully but fails during CREATE_CHILD_SA. The engineer captures the debug output from the initiating Cisco Secure Firewall. Which action must be performed to resolve the issue?


A.

Align the protected network definitions on both firewalls so that the local and remote traffic selectors proposed during CREATE_CHILD_SA match on both peers.


B.

Change the IPsec encryption algorithm from AES-256 to AES-128 on the initiating firewall and redeploy the VPN policy.


C.

Extend the IKE SA lifetime on both firewalls to give CREATE_CHILD_SA sufficient time to complete the negotiation before the Phase 1 SA expires.


D.

Remove DH Group 19 from the IPsec proposal on the initiating FTD because the TS_UNACCEPTABLE notification indicates that the responder does not support the proposed PFS group.


Get Premium 350-701 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.