Soru

Zorluk: OrtaVirtual Private Networks and Remote Access Security

An organization is implementing a client-based Remote Access VPN using L2TP/IPsec to provide secure connectivity for remote workers through perimeter firewalls and Network Address Translation (NAT) gateways. Which of the following protocol requirements and firewall rules are necessary to establish and maintain this VPN connection? (Select TWO.)

  1. UDP port 500 must be allowed inbound and outbound for Internet Key Exchange (IKE) Security Association (SA) negotiations.Cevap
  2. UDP port 4500 must be permitted to support IPsec NAT-Traversal (NAT-T) when clients reside behind NAT devices.Cevap
  3. C
    TCP port 1701 must be permitted through the firewall to provide payload encryption for the un-encapsulated L2TP tunnel.
  4. D
    IP Protocol 51 (Authentication Header) must be enabled to encrypt data payloads and preserve integrity across NAT gateways.

Cevap

UDP port 500 for IKE negotiations and UDP port 4500 for NAT-Traversal are both required for L2TP/IPsec remote access VPN connections across NAT gateways.
For an L2TP/IPsec VPN connection to successfully navigate boundary firewalls and NAT devices, UDP port 500 must be opened for IKE authentication and key exchange, and UDP port 4500 must be permitted to allow NAT-Traversal (NAT-T) encapsulation of ESP data packets.

Adım Adım Çözüm

1
Identify key protocols for IPsec handshake and negotiation
Recognize that Internet Key Exchange (IKE) uses UDP port 500 to authenticate peers and set up Security Associations.
Without allowing UDP port 500 through the boundary firewall, initial key exchange cannot complete.
2
Analyze the impact of Network Address Translation (NAT) on IPsec traffic
Determine that NAT-Traversal (NAT-T) encapsulates ESP traffic inside UDP port 4500 headers when NAT is detected between endpoints.
Standard IPsec ESP (IP Protocol 50) packets lack port numbers and often fail or experience issues when traversing NAT unless wrapped in UDP 4500.
3
Evaluate distractor choices regarding transport protocols and encryption roles
Identify that L2TP uses UDP port 1701 (not TCP) and provides no native encryption, while AH (IP Protocol 51) provides no encryption and fails when modified by NAT.
L2TP relies on IPsec for confidentiality, and ESP with NAT-T (UDP 4500) must be used instead of AH for NAT compatibility.

Anahtar Kavram

L2TP/IPsec Protocol Requirements and Firewall NAT Traversal
Bu soruyu puanla