Exam 300-730 All QuestionsBrowse all questions from this exam
Question 84

Refer to the exhibit. An IKEv2 site-to-site tunnel between an ASA and a remote peer is not building successfully. What will fix the problem based on the debug output?

    Correct Answer: C

    Based on the debug output, the error message indicates that there was no IPSEC policy found for the received Traffic Selector (TS). This suggests that the issue is related to the identification of the traffic to be tunneled, which is configured using crypto access lists (ACLs). Therefore, correcting the crypto access lists on both VPN devices to properly match the interesting traffic will resolve the issue.

Discussion
[Removed]Option: C

TS - traffic selector - which traffic to be tunneled. TS_UNACCEPTABLE means the interesting traffic doesn't match

shadow2020Option: A

the error message says, "There was no IPSEC POLICY found for received TS" TS = Traffic selector (IP), so this means nothing to do with the IP but rather IPSec policy

BackupzOption: C

C - need to modify ACLs

AF_NickOption: C

C - need to modify ACLs to properly identify interesting traffic

7df6b1cOption: A

I think A .. Why should we correct on BOTH devices the ACL? Makes no sense

kylesam2017Option: A

Provided answer seems to be correct.

kylesam2017Option: A

'A', seems to be the correct answer here.

mpls_linkOption: D

Traffic Selector mismatch, check the ACL for the interesting traffic on both nodes