Exam PCNSE All QuestionsBrowse all questions from this exam
Question 592

Which two are required by IPSec in transport mode? (Choose two.)

    Correct Answer: A, D

    IPSec in transport mode typically requires auto-generated keys for secure communication and can use various Diffie-Hellman groups for key exchange, including DH-group 20 (ECP-384 bits). NAT Traversal and IKEv1 are not specifically required by IPSec in transport mode.

Discussion
ThunnuOptions: AD

AD https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/ipsec-transport-mode

hcir

NAT traversal is not supported in transport mode because only the payload is encrypted. IKEv1 is not supported, it is probably a vendor decision.

PacketsDownRange99Options: AD

Agree AD https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-new-features/networking-features/ipsec-transport-mode