H12-731-ENU 試験問題を無料オンラインアクセス
| 試験コード: | H12-731-ENU |
| 試験名称: | HCIE-Security (Huawei Certified Internetwork Expert-Security) |
| 認定資格: | Huawei |
| 無料問題数: | 205 |
| 更新日: | 2026-07-18 |
A customer network topology is shown in the figure.
An LZTP tunnel is established between the PC and the FW, with the PC as the client and the FW as the LNS side. After the administrator completes the configuration, it is found that the L2TP tunnel cannot be established successfully.
Execute the command debug l2tp packet in the user view to enable the debug switch, and see the following debug information:
USG %%01L2TP/8/L2TDBG (d): L2TP::Check SCCRQ MSG Type 1
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Protocol version: 100
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Framing capability: 1
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Bearer capability, value: 0
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Firmware revision, value: 1200
USG %%01L2TP/8/L2TDBG (d): L2TP::Parse AVP Host name, value: maple-54b160e59
USG %%01L2TP/8/L2TDBG (d): L2TP::requested Host isn't in the define l2tp group, refuse the requested
USG %%01L2TP/8/L2TDBG (d): L2TP::Clear Calls On Tunnel ID=1 Reason=1
Based on the above information, which failure analysis option is correct?
View the session table information on the firewall as follows:
[USG] display firewall session table verbose
icmp VPN: public --> public
Zone: trust --> untrust TTL: 00:00:20 Left: 00:00:15
Interface: GigabitEthernet0/0/4 Nexthop: 2.2.2.2 MAC: 00-00-00-00-00-00
<-- packets: 0 bytes: 0 --> packets: 5 bytes: 420
192.168.1.2:44012[1.1.1.3:6103] --> 2.2.2.2:2048
The following descriptions are correct: