ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your organization must connect its on-premises data center to an Amazon VPC using an IPsec site-to-site VPN. The traffic path crosses one or more upstream routers that perform network address translation (NAT). To ensure the tunnel still provides confidentiality and integrity across these devices, which IPsec configuration must you enable on both VPN endpoints?
Use IPsec transport mode instead of tunnel mode to bypass NAT devices
Replace Encapsulating Security Payload with Authentication Header (AH) to tolerate header changes
Enable IPsec NAT Traversal (encapsulate ESP in UDP port 4500 while using tunnel mode)
Disable Perfect Forward Secrecy in IKE Phase 2 to prevent rekeying conflicts with NAT
NAT devices rewrite the outer IP header and typically block IP protocol 50, which prevents plain ESP packets from reaching the peer. IPsec's NAT Traversal (NAT-T) feature encapsulates ESP in UDP datagrams on port 4500; the NAT device treats the traffic like ordinary UDP, allowing it to pass while the inner ESP payload remains encrypted and authenticated. Switching to transport mode does not solve the problem, Authentication Header fails because it verifies the IP header that NAT modifies, and disabling Perfect Forward Secrecy has no bearing on NAT behaviour.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IPsec NAT Traversal and why is it used?
Open an interactive chat with Bash
What is the difference between IPsec tunnel mode and transport mode?
Open an interactive chat with Bash
Why does Authentication Header (AH) fail in environments with NAT devices?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Cryptography
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .