2V0-41.24 exam dumps

2V0-41.24 practice question 391 of 462

VMware Certified Professional - Network Virtualization 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-41.24 Question 391

Select 2

Your organization needs to establish a secure connection between two sites using VMware NSX. As a network administrator, you are tasked with configuring an IPSec VPN service. Which two configuration steps are mandatory to successfully create an IPSec VPN service in NSX?

  1. A

    Create a logical switch and attach it to the Tier-1 gateway.

  2. B

    Define the VPN local endpoint with the appropriate IP address.

  3. C

    Configure the encryption and authentication protocols for the IPSec policy.

  4. D

    Set up a Distributed Firewall (DFW) rule to allow IPSec traffic.

  5. E

    Activate the BGP routing protocol on both gateways.

Show answer and explanation

Correct answers: B, C

Explanation

To successfully create an IPSec VPN service in VMware NSX, you must define the VPN local endpoint, which specifies the IP address used for the connection, and configure the encryption and authentication protocols to secure the tunnel. These are critical and mandatory steps for establishing an IPSec VPN. Other options, such as creating logical switches or configuring BGP, may be part of broader network configurations but are not directly required for the IPSec VPN setup.

  • A. Incorrect.

    Creating a logical switch is not part of the mandatory steps to configure an IPSec VPN service. Logical switches are used for segmenting networks but are not directly related to IPSec VPN configuration.

  • B. Correct.

    Defining the VPN local endpoint is a required step to establish the IPSec tunnel. It identifies the local IP address used for the VPN connection.

  • C. Correct.

    Configuring encryption and authentication protocols is essential for securing IPSec traffic. Without this step, the VPN service cannot encrypt or authenticate traffic.

  • D. Incorrect.

    While allowing IPSec traffic in the Distributed Firewall is good practice, it is not a mandatory step for configuring the IPSec VPN service itself. The firewall rules only control traffic flow.

  • E. Incorrect.

    BGP routing is unrelated to setting up an IPSec VPN service. BGP might be used for dynamic routing in other scenarios, but it is not required for IPSec VPN configuration.

Timed practice exam

Take a 2V0-41.24 practice test under exam conditions

55 questions in 135 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam