Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 145 Topic 15 Discussion

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 145 Topic 15 Discussion

350-701 Exam Topic 15 Question 145 Discussion:
Question #: 145
Topic #: 15

A security engineer is deploying an IPsec site-to-site VPN between headquarters and a remote plant, protected by Cisco Secure Firewall Threat Defense managed by Cisco Secure Firewall Management Center. The following configurations have already been completed:

    Matching IKEv2 proposals, preshared keys, and IPsec transform sets

    Access control rules permitting the traffic

    Crypto maps applied to the outside interfaces

    VPN traffic exempted from inspection

During a packet capture on the firewall, the engineer observes that the traffic is translated to the public IP address, preventing tunnel establishment. Which configuration action must be performed next?


A.

Configure NAT exemption for traffic between the interesting subnet pairs.


B.

Create a tunnel group with preshared-key authentication under connection profiles.


C.

Enable IKEv2 fragmentation on both peers to reduce packet size.


D.

Attach the new VPN policy to the global prefilter default action.


Get Premium 350-701 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.