An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)
第1题:
You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()
第2题:
Based on the configuration shown in the exhibit, what will happen to the traffic matching thesecurity policy?() [edit schedulers] user@host# showscheduler now { monday all-day; tuesday exclude; wednesday { start-time 07:00:00 stop-time 18:00:00; } thursday { start-time 07:00:00 stop-time 18:00:00; } } [edit security policies from-zone Private to-zone External] user@host# showpolicy allowTransit { match { source-address PrivateHosts; destination-address ExtServers; application ExtApps; } then { permit { tunnel { ipsec-vpn myTunnel; } } } scheduler-name now; }
第3题:
To securely transport EIGRP traffic, a network administrator will build VPNs between sites. What is the best method to accomplish the transport of EIGRP traffic?()
第4题:
Which of the following protocols would MOST likely be used in the establishment of an IPSec VPN tunnel?()
第5题:
Regarding an IPsec security association (SA), which two statements are true?()
第6题:
IPSec in tunnel mode
IPSec in transport mode
GRE with IPSec in transport mode
GRE with IPSec in tunnel mode
第7题:
Twenty bytes of header will be replaced with five bytes.
If the IPSec transform set includes Authentication Header, the receiving IPSec peer will discard the packets.
The IPSec packets will be dropped by Router A's compression logic.
The voice packets will not be compressed.
第8题:
L2F tunnel
L2TP tunnel
GRE tunnel
ISAKMP tunnel
第9题:
Only main mode can be used for IKE negotiation
A local-identity must be defined
It must be the initiator for IKE
A remote-identity must be defined
第10题:
When the packet received on the LAN interface is permitted by the ACL listed on the tunnel greacl command under the incoming interface
When routing the packet, matching a route whose outgoing interface is the GRE tunnel interface
When routing the packet, matching a route whose outgoing interface is the IPsec tunnel interface
When permitted by an ACL that was referenced in the associated crypto map
第11题:
IPSec in tunnel mode
IPSec in transport mode
GRE with IPSec in transport mode
GRE with IPSec in tunnel mode
第12题:
VPN tunnel authentication is part of the IKE specification.
VPN tunnel authentication does not control which end user can use the IPSec SA (VPN tunnel).
User authentication is used to control access for a specific user ID, and can be used with or without a VPN tunnel for network access authorization.
802.1X with EAP-TLS (X.509 certificates) can be used to authenticate an IPSec tunnel.
第13题:
What is not a difference between VPN tunnel authentication and per-user authentication?()
第14题:
What is true about Quality of Service (QoS) for VPNs?()
第15题:
Which of the following protocols would MOST likely be used in the establishment of an IPSec VPN tunnel?()
第16题:
Which statement is true regarding IPsec VPNs?()
第17题:
Which two configuration elements are required for a route-based VPN?()
第18题:
allows dynamic routing over the tunnel
supports multi-protocol (non-IP) traffic over the tunnel
reduces IPsec headers overhead since tunnel mode is used
simplifies the ACL used in the crypto map
uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration
第19题:
set policy tunnel-traffic then tunnel remote-vpn
set policy tunnel-traffic then permit tunnel remote-vpn
set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn permit
set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
第20题:
The traffic is permitted through the myTunnel IPSec tunnel only on Tuesdays.
The traffic is permitted through the myTunnel IPSec tunnel daily, with the exception of Mondays.
The traffic is permitted through the myTunnel IPSec tunnel all day on Mondays, Wednesdays between 7:00 am and 6:00 pm, and Thursdays between 7:00 am and 6:00 pm.
The traffic is permitted through the myTunnel IPSec tunnel all day on Mondays, Wednesdays between 6:01 pm and 6:59 am, and Thursdays between 6:01 pm and 6:59 am.
第21题:
The crypto ACL number
The IPSEC mode (tunnel or transport)
The GRE tunnel interface IP address
The GRE tunnel source interface or IP address, and tunnel destination IP address
The MTU size of the GRE tunnel interface
第22题:
IKE gateway
secure tunnel interface
security policy to permit the IKE traffic
security policy referencing the IPsec VPN tunnel
第23题:
Dead Peer Detection (DPD)
CDP
isakmp keepalives
GRE keepalive mechanism
The hello mechanism of the routing protocol across the IPsec tunnel