問題文
A network team plans an IPsec tunnel from its edge router to Secure Access and asks which negotiation settings are safe to keep. What does the documentation state about the supported parameters?
選択肢
- Only IKEv1 is supported for the first phase, and Dead Peer Detection is left to the remote end as Secure Access does not send those probes.
- Both IKEv1 and IKEv2 are supported, and Perfect Forward Secrecy has to be enabled on the peer end, before the tunnel is allowed to come up at all.
- Only IKEv2 is supported, and a tunnel that enables Perfect Forward Secrecy can come up yet fail to rekey on a reconnection, which costs service until it is rebuilt.
- Any parameter combination that the remote device offers is accepted, as Secure Access negotiates down to whatever the device supports.