Juniper Networks Certified Associate Junos JNCIA Junos · Free Practice Question Medium
Question 5

An IPsec VPN must be established between the Remote and Corporate sites.
Which IPsec VPN feature must be enabled to establish the connection successfully?
-
A
Main mode must be configured on the IKE gateway
-
B
Aggressive mode must be configured on the IKE gateway
-
C
Aggressive mode must be configured on the IPsec VPN
-
D
Main mode must be configured on the IPsec VPN
Reveal correct answer
Correct answer: B
Explanation
In the shown exhibit, the remote gateway has a dynamic IP address.
When IKEv1 is used with dynamic endpoint VPNs, the IKE policy must be configured for aggressive mode.
Further reading - https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-ipsec-vpn-configuration-overview.html
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
