🔥 3-day streak
Cisco Designing and Implementing Secure Cloud Connectivity ENCC (300-440)39 / 128
Question 39 of 128

An engineer troubleshoots a route-based IPsec tunnel from a Cisco IOS XE router to a native Azure VPN gateway. The IOS XE router sits behind a corporate firewall that performs PAT (NAT overload) on its public interface. IKEv2 negotiation begins but never completes; 'show crypto ikev2 sa' shows the SA stuck in the IN-NEG state, and debugs show the Azure gateway is not authenticating the peer. The pre-shared keys, transform sets, and DH groups all match. What is the MOST likely cause?

Reviewed for accuracy · Report an issueNext question