An organization is implementing a client-based Remote Access VPN using L2TP/IPsec to provide secure connectivity for remote workers through perimeter firewalls and Network Address Translation (NAT) gateways. Which of the following protocol requirements and firewall rules are necessary to establish and maintain this VPN connection? (Select TWO.)
- UDP port 500 must be allowed inbound and outbound for Internet Key Exchange (IKE) Security Association (SA) negotiations.Cevap
- UDP port 4500 must be permitted to support IPsec NAT-Traversal (NAT-T) when clients reside behind NAT devices.Cevap
- CTCP port 1701 must be permitted through the firewall to provide payload encryption for the un-encapsulated L2TP tunnel.
- DIP Protocol 51 (Authentication Header) must be enabled to encrypt data payloads and preserve integrity across NAT gateways.
Cevap
UDP port 500 for IKE negotiations and UDP port 4500 for NAT-Traversal are both required for L2TP/IPsec remote access VPN connections across NAT gateways.
For an L2TP/IPsec VPN connection to successfully navigate boundary firewalls and NAT devices, UDP port 500 must be opened for IKE authentication and key exchange, and UDP port 4500 must be permitted to allow NAT-Traversal (NAT-T) encapsulation of ESP data packets.
Adım Adım Çözüm
Anahtar Kavram
L2TP/IPsec Protocol Requirements and Firewall NAT Traversal