Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam PCNSE All Questions

View all questions & answers for the PCNSE exam

Exam PCNSE topic 1 question 437 discussion

Actual exam question from Palo Alto Networks's PCNSE
Question #: 437
Topic #: 1
[All PCNSE Questions]

An engineer troubleshooting a site-to-site VPN finds a Security policy dropping the peer’s IKE traffic at the edge firewall. Both VPN peers are behind a NAT, and NAT-T is enabled.

How can the engineer remediate this issue?

  • A. Add a Security policy to allow UDP/500.
  • B. Add a Security policy to allow the IKE application.
  • C. Add a Security policy to allow the IPSec application.
  • D. Add a Security policy to allow UDP/4501.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
MrR0bot
Highly Voted 1 year, 8 months ago
Selected Answer: C
Looks like should be C according to below https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFRCA0 The ipsec application contains the following sub-apps: ike ipsec-ah ipsec-esp ipsec-esp-udp(NAT-T) The sub-apps above are allowed implicitly when the ipsec application is configured as allowed.
upvoted 11 times
...
Rowdy_47
Highly Voted 1 year, 7 months ago
A: Add a Security policy to allow UDP/500 - will not work as stated from others when NAT-T is enabled it will also use UDP4500 https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC "To check if NAT-T is enabled, packets will be on port 4500 instead of 500 from the 5th and 6th messages of main mode." B: Add a Security policy to allow the IKE application. - will not work as per the above D:Add a Security policy to allow UDP/4501 - will not work as per the above C: Add a Security policy to allow the IPSec application. - having checked on PANOS 10.2 the IPSec application has 4 sub(?) applications - ike (Standard Ports: tcp/500, udp/500) - ipsec-ah (Standard Ports: IP Protocol 51) - ipsec-esp (Standard Ports: IP Protocol 50) - ipsec-esp-udp (Standard Ports: udp/4500, udp/4501)
upvoted 8 times
Mocix
10 months ago
I checked with 11.0.0 and ike is not under ipsec.
upvoted 1 times
Pacheco
8 months ago
Check again because it's there ;)
upvoted 2 times
...
...
...
Cro13
Most Recent 1 month ago
Selected Answer: C
behind a NAT. So only C is possible
upvoted 1 times
...
ali_sh85
2 months, 3 weeks ago
Selected Answer: C
*C is correct
upvoted 1 times
...
ali_sh85
3 months ago
Selected Answer: B
Answer should be B, it is dropping the IKE and also NAT-T works on port 4500 not 4501
upvoted 2 times
...
nolox
4 months, 1 week ago
Selected Answer: B
In Objects > Applications it can be seen that ike app uses tcp/500 and/or udp/500 and that it doesn't depend on any other app (for example ipsec). Since PA is always recommending to use app ID I would choose B.
upvoted 1 times
...
Marshpillowz
8 months, 2 weeks ago
Selected Answer: C
Answer is C
upvoted 1 times
...
JRKhan
9 months ago
Selected Answer: C
I believe its safe to allow IPsec application which will encompass both udp/500 and udp/4500, udp/4501.
upvoted 1 times
...
Metgatz
10 months ago
Selected Answer: C
Ipsec apps include ike an the other ipsec. Option C
upvoted 1 times
...
Metgatz
10 months ago
Ipsec apps include ike an the other ipsec. Option C
upvoted 1 times
...
sov4
1 year, 2 months ago
Selected Answer: C
Should be C. Tested in my lab. The IPSec app contains ike, ipsec-ha, ipsec-esp, and ipsec-udp, which covers everything in the question.
upvoted 2 times
...
jhoncena
1 year, 6 months ago
Selected Answer: C
Should be C as it will include other sub APPs... IKE 500 for answer A is not right as NAT-T is enabled
upvoted 3 times
...
kewokil120
1 year, 7 months ago
Selected Answer: C
adding my vote
upvoted 4 times
...
Rowdy_47
1 year, 7 months ago
Selected Answer: C
adding my vote
upvoted 3 times
...
TheIronSheik
1 year, 7 months ago
FWIW, this was a PCNSE test question in Jan 2023.
upvoted 6 times
...
GohanF2
1 year, 8 months ago
I had done this before, and it works by just allowing the IKE application in the policy rule. I will vote for B
upvoted 2 times
...
DenskyDen
1 year, 8 months ago
I believe it is B. because as mentioned above NAT-T is enabled so ,packets will be on port 4500 instead of 500 from the 5th and 6th messages of main mode. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClivCAC
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...