Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 43 Topic 5 Discussion

Cisco Implementing and Operating Cisco Security Core Technologies (SCOR 350-701 v2.0) 350-701 Question # 43 Topic 5 Discussion

350-701 Exam Topic 5 Question 43 Discussion:
Question #: 43
Topic #: 5

Refer to the exhibit.

350-701 Question 43

During the rollout of a new site-to-site VPN between a headquarters Cisco Secure Firewall Threat Defense device and a partner firewall, the tunnel never completes IKEv1 Phase 1 and remains in the MM_WAIT_MSG_6 state. Reachability between the firewalls over the Internet is verified, ISAKMP UDP port 500 is permitted end-to-end, and the IKE Phase 1 policy parameters—including encryption, hashing, DH group, and lifetime—match exactly on both ends. Which configuration action must be performed to resolve the issue?


A.

Configure matching peer-identity values under each tunnel group on both endpoints.


B.

Add the same pre-shared key on both peers within their tunnel-group attributes.


C.

Implement identical Diffie-Hellman group numbers within the active IKEv1 policy.


D.

Apply equivalent transform sets and lifetimes inside the crypto-map entries.


Get Premium 350-701 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.