Quote:
Originally Posted by godspeedcapri I guess 'E' would be right. Performing step 2 just adds the Madrid object to the mesh community. You would need to perform step 4 for configuring the Madrid VPN properties. Traditional mode gives more granular control over the type of encryption to use,keys and certificates. Checkout Chapter 11 VPN, Pg 381, CCSA NGX Syngress Guide. |
Good!! I'm reading this chapter right now and it states "The primary difference between the two approaches is that instead of the gateway deriving all of its encryption settings from the VPN community it belongs to, they are specified in the properties of each gateway object".
So it's not required all the times, but you may want to do so to have more granular control, as you said.
If the question had said that Barak had already configured the Settings on the VPN Community , then it would be just a matter of adding Madrid's gateway on this community.
As the question don't mention nothing about this, I agree we would have to configure the Traditional Mode in Madrid gateway. But anyway, as you guys have already said, this should be configured on all 3 gateways...
Do you think the problem is that the question is missing some information ? :P
Thanks a lot for your posts!!!
Robori