You have an Azure virtual network (Vnet1) and an on-premises network with policy-based VPN devices. In Vnet1 you deployed a virtual network gateway named GW1 using SKU VpnGw1 and configured as route-based. Before creating the Site-to-Site connection so the on-premises network can connect to the route-based GW1, what must you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: Set IPsec / IKE policy to Custom..
Why this is the answer
Policy-based VPN devices require specific IPSec/IKE policies to establish a Site-to-Site VPN connection with Azure route-based VPN gateways. By default, Azure route-based gateways use a default set of IPSec/IKE parameters that are compatible with other route-based VPN devices. However, policy-based VPN devices often have more restrictive or different requirements for these parameters (e.g., encryption algorithms, hashing algorithms, DH groups, SA lifetimes). Therefore, you must configure a custom IPSec/IKE policy on the Azure VPN gateway to match the parameters expected by the on-premises policy-based VPN device. Setting Connection Mode to ResponderOnly or enabling BGP are not prerequisites for establishing the initial connection with a policy-based VPN device. Using Azure Private IP Address is not relevant to this scenario.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed