2V0-41.24 Question 379
Single answerAn organization is deploying a multi-site NSX-T Data Center environment and needs to establish secure communication between two sites over the public internet. The goal is to ensure data encryption and site-to-site connectivity for workloads. Which VPN type should be configured in NSX-T to meet this requirement?
- A
Layer 2 VPN
- B
IPsec VPN
- C
SSL VPN-Plus
- D
GRE Tunnel
Show answer and explanation
Correct answer: B
Explanation
To secure communication between two NSX-T sites over the public internet, IPsec VPN is the most appropriate solution as it offers encryption, authentication, and integrity, ensuring that data remains secure during transit. Other options do not meet the requirement for secure site-to-site connectivity in this scenario.
- A. Incorrect.
Layer 2 VPN is used to extend Layer 2 broadcast domains between sites, which is not suitable for secure site-to-site communication over the internet.
- B. Correct.
IPsec VPN provides secure site-to-site communication using encryption and is the correct choice for connecting two NSX-T sites over the public internet.
- C. Incorrect.
SSL VPN-Plus is typically used for remote user access, not for site-to-site communication between NSX-T sites.
- D. Incorrect.
GRE Tunnel does not provide encryption by default and would not meet the requirement for secure communication over the public internet.