Valid 400-101 Dumps shared by ExamDiscuss.com for Helping Passing 400-101 Exam! ExamDiscuss.com now offer the newest 400-101 exam dumps, the ExamDiscuss.com 400-101 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com 400-101 dumps with Test Engine here:
Refer to the exhibit. What is a possible reason for the IPSEC tunnel not establishing?
Correct Answer: D
Explanation/Reference: Explanation: Proxy Identities Not Supported This message appears in debugs if the access list for IPsec traffic does not match. 1 1 1 d00h: IPSec(validate_transform_proposal): proxy identities not supported d00h: ISAKMP: IPSec policy invalidated proposal d00h: ISAKMP (0:2): SA not acceptable! The access lists on each peer needs to mirror each other (all entries need to be reversible). This example illustrates this point. Peer A access-list 150 permit ip 172.21.113.0 0.0.0.255 172.21.114.0 0.0.0.255 access-list 150 permit ip host 15.15.15.1 host 172.21.114.123 Peer B access-list 150 permit ip 172.21.114.0 0.0.0.255 172.21.113.0 0.0.0.255 access-list 150 permit ip host 172.21.114.123 host 15.15.15.1 Reference: http://www.cisco.com/c/en/us/support/docs/security-vpn/ipsec-negotiation-ike-protocols/5409- ipsec-debug-00.html#proxy