2V0-41.24 exam dumps

2V0-41.24 practice question 187 of 462

VMware Certified Professional - Network Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-41.24 Question 187

Single answer

You are configuring an IPSec VPN between two NSX-T Data Center environments to securely connect workloads across sites. During the setup, you notice that the VPN tunnel is not establishing. Upon reviewing the configuration, you identify the following settings:

  • Both sites are using pre-shared keys for authentication.
  • The encryption algorithm is set to AES-256.
  • IKEv2 is configured as the protocol.
  • Site A has the local subnet 10.10.10.0/24 configured, but Site B has specified 10.10.20.0/24 for the remote subnet.

What is the most likely reason the VPN tunnel is failing to establish?

  1. A

    The encryption algorithm AES-256 is not supported for IPSec VPNs in NSX-T.

  2. B

    The pre-shared key authentication method is not supported with IKEv2.

  3. C

    The subnet mismatch between Site A and Site B is causing the tunnel to fail.

  4. D

    IKEv2 is not supported for NSX-T IPSec VPN configurations.

Show answer and explanation

Correct answer: C

Explanation

For an IPSec VPN to establish successfully, the local and remote subnets must match on both ends of the connection. In this scenario, Site A is configured with 10.10.10.0/24 as the local subnet, while Site B is expecting 10.10.20.0/24 as the remote subnet. This mismatch in traffic selectors causes the VPN negotiation to fail. The other options are incorrect as they describe features or configurations that are supported in NSX-T.

  • A. Incorrect.

    AES-256 is a supported encryption algorithm for IPSec VPNs in NSX-T and is commonly used for its strong encryption.

  • B. Incorrect.

    Pre-shared key authentication is supported with IKEv2 in NSX-T and is a valid configuration option.

  • C. Correct.

    The mismatch between the local and remote subnets in the IPSec VPN configuration will prevent the tunnel from being established because both sites need to agree on the traffic selectors for the VPN.

  • D. Incorrect.

    IKEv2 is supported in NSX-T IPSec VPN configurations and is often used for its improved security and efficiency compared to IKEv1.

Timed practice exam

Take a 2V0-41.24 practice test under exam conditions

55 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam