In AOS10 Tunneled mode, which component handles IPSec Phase 1 negotiation on the Access Point side?

Prepare for the HPE Aruba Networking Certification. Enhance your skills with interactive quiz formats, detailed explanations, and valuable study resources. Ensure you're ready for the exam!

Multiple Choice

In AOS10 Tunneled mode, which component handles IPSec Phase 1 negotiation on the Access Point side?

Explanation:
In Tunneled mode, the edge device that sits at the user/device edge is responsible for establishing the secure tunnel by running the IKE Phase 1 negotiation with the remote gateway. This phase creates the IKE SA, authenticates the peers, and negotiates cryptographic parameters so that IPsec can be built for the data tunnel. Therefore, the Access Point handles the Phase 1 negotiation on its side to set up the tunnel to the overlay gateway. The other components are not performing this AP-side Phase 1 negotiation. The gateway or a designated gateway role refers to the remote end of the tunnel, and the Overlay Tunnel Orchestrator coordinates tunnels at a higher level rather than conducting the AP-side IPsec IKE Phase 1.

In Tunneled mode, the edge device that sits at the user/device edge is responsible for establishing the secure tunnel by running the IKE Phase 1 negotiation with the remote gateway. This phase creates the IKE SA, authenticates the peers, and negotiates cryptographic parameters so that IPsec can be built for the data tunnel. Therefore, the Access Point handles the Phase 1 negotiation on its side to set up the tunnel to the overlay gateway.

The other components are not performing this AP-side Phase 1 negotiation. The gateway or a designated gateway role refers to the remote end of the tunnel, and the Overlay Tunnel Orchestrator coordinates tunnels at a higher level rather than conducting the AP-side IPsec IKE Phase 1.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy