🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)22 / 128
Question 22 of 128
A network engineer is configuring a route-based IPsec (VTI) tunnel from an on-premises Cisco IOS XE router to a native Azure VPN Gateway (route-based, Generation 2). The IKEv2 SA is failing to establish, and debugs on the IOS XE router show the negotiation stalling during the IKE_SA_INIT exchange. The engineer confirms that the pre-shared key, IKEv2 encryption, and integrity algorithms are all correctly matched to Azure's default IPsec/IKE policy. Which additional IKEv2 proposal parameter must the engineer verify matches the Azure default policy to allow IKE_SA_INIT to complete?
Reviewed for accuracy · Report an issueNext question