Which TWO configuration items must match on both the OCI CPE/VPN gateway and the on-premises customer-premises equipment (CPE) router to successfully establish an IPSec VPN tunnel? (Choose TWO)
Trap 1: The OCI console password of the administrator who created the VPN.
Console passwords are irrelevant to IPSec tunnel establishment.
Trap 2: The Oracle Cloud Infrastructure region home datacenter geographic…
Geographic coordinates have no impact on IPSec VPN configuration.
- A
IKE (Internet Key Exchange) phase 1 and phase 2 encryption and authentication algorithms.
Cryptographic settings (encryption, hashing, DH groups) must match for Phase 1 and Phase 2.
- B
The OCI console password of the administrator who created the VPN.
Why wrong: Console passwords are irrelevant to IPSec tunnel establishment.
- C
The Oracle Cloud Infrastructure region home datacenter geographic coordinates.
Why wrong: Geographic coordinates have no impact on IPSec VPN configuration.
- D
The exact model number and firmware version of the on-premises router.
While various vendors are supported, matching exact vendor parameters is critical, though vendor models themselves don't strictly need to be identical (though settings do). Wait, let's look at option D versus E. Option D says exact model number which is false (any CPE is supported as long as standards match). Let's review the options.
- E
Pre-shared key (PSK) or shared secret authentication credentials.
Both ends must be configured with the identical pre-shared key to authenticate the tunnel.