Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam JN0-231 All Questions

View all questions & answers for the JN0-231 exam

Exam JN0-231 topic 1 question 37 discussion

Actual exam question from Juniper's JN0-231
Question #: 37
Topic #: 1
[All JN0-231 Questions]

You are creating Ipsec connections.
In this scenario, which two statements are correct about proxy IDs? (Choose two.)

  • A. Proxy IDs are used to configure traffic selectors.
  • B. Proxy IDs are optional for Phase 2 session establishment.
  • C. Proxy IDs must match for Phase 2 session establishment.
  • D. Proxy IDs default to 0.0.0.0/0 for policy-based VPNs.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
achon
Highly Voted 1 year, 7 months ago
Selected Answer: CD
https://supportportal.juniper.net/s/article/SRX-Understanding-how-proxy-IDs-are-generated-in-route-based-and-policy-based-VPNs?language=en_US
upvoted 5 times
OJ1
1 year, 2 months ago
CD are the best answers
upvoted 1 times
...
...
westh4m1234
Most Recent 8 months, 2 weeks ago
This question is doing my head in - its not clear if they are asking about route-based or policy based because for route-based answer would be A+D however for policy-based it would be C+D
upvoted 1 times
...
westh4m1234
8 months, 3 weeks ago
SORRY MEANT TO SAY A+B ARE CORRECT FOR POLICY BASED VPN
upvoted 1 times
...
westh4m1234
8 months, 3 weeks ago
after having a good read check the below statement i think its A+D as the answer Proxy ID generation for ROUTE-BASED VPNs can be defined explicitly. If it is not defined, a default proxy ID will be used of 0.0.0.0 if no traffic selectors are configured at all then the default proxy id will be used and must match both peers, Proxy ID generation for POLICY-BASED VPNs is based on the security policy that is bound to the VPN , and cannot be overwritten with the proxy-identity command under the set security ipsec vpn <vpn> ike proxy-identity stanza.
upvoted 1 times
...
westh4m1234
8 months, 3 weeks ago
CD- Proxy IDs are a validated item during VPN tunnel establishment with the proxy IDs of the VPN peers needing to be an inverse match of one another: SRX PEER Local 192.168.1.0/24 \ / Local 10.10.10.5/32 Remote 10.10.10.5/32 / \ Remote 192.168.1.0/24 Proxy ID generation for route-based VPNs can be defined explicitly. If it is not defined, a default proxy ID will be used of 0.0.0.0 if no traffic selectors are configured at all then the default proxy id will be used and must match both peers
upvoted 1 times
...
westh4m1234
9 months ago
C+D - i agree with 66dc178 When no proxy-identity is defined, the system uses a default proxy-identity, which is 0.0.0.0
upvoted 1 times
...
66dc178
10 months ago
Selected Answer: CD
In the absence of specific proxy ID configurations in policy-based VPNs, the default traffic selectors are considered to be 0.0.0.0/0, indicating that all traffic is eligible for the VPN tunnel, subject to the policy definitions. This default setting facilitates the tunneling of all traffic as per the defined policies unless more specific traffic selectors are configured.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...