mode
preshared key
external interface
security proposals
dead peer detection settings
第1题:
A. [edit security ipsec] user@host# show proposal ike1-proposal { protocol esp; authentication-algorithm hmac-md5-96; encryption-algorithm 3des-cbc; lifetime-seconds 3200; }policy ipsec1-policy { perfect-forward-secrecy { keys group2; } proposals ike1-proposal; } vpn VpnTunnel { interface ge-0/0/1.0; ike { gateway ike1-gateway; ipsec-policy ipsec1-policy; } establish-tunnels immediately; }
B. [edit security ipsec] user@host# show proposal ike1-proposal { protocol esp; authentication-algorithm hmac-md5-96; encryption-algorithm 3des-cbc; lifetime-seconds 3200; } policy ipsec1-policy { perfect-forward-secrecy { keys group2; } proposals ike1-proposal; } vpn VpnTunnel { interface st0.0; ike { gateway ike1-gateway; ipsec-policy ipsec1-policy; } establish-tunnels immediately; }
C. [edit security ipsec] user@host# show proposal ike1-proposal { protocol esp; authentication-algorithm hmac-md5-96; encryption-algorithm 3des-cbc; lifetime-seconds 3200;} policy ipsec1-policy { perfect-forward-secrecy { keys group2; } proposals ike1-proposal; } vpn VpnTunnel { bind-interface ge-0/0/1.0; ike { gateway ike1-gateway; ipsec-policy ipsec1-policy; } establish-tunnels immediately; }
D. [edit security ipsec] user@host# show proposal ike1-proposal { protocol esp; authentication-algorithm hmac-md5-96; encryption-algorithm 3des-cbc; lifetime-seconds 3200; }policy ipsec1-policy { perfect-forward-secrecy { keys group2; } proposals ike1-proposal; } vpn VpnTunnel { bind-interface st0.0; ike { gateway ike1-gateway; ipsec-policy ipsec1-policy; } establish-tunnels immediately; }
第2题:
Which three parameters are configured in the IKE policy?()
第3题:
Which two configuration elements are required for a policy-based VPN?()
第4题:
Which three parameters are configured in the IKE policy? ()(Choose three.)
第5题:
Which two parameters are determined during PPP LCP negotiation?()
第6题:
force infrastructure devices to associate only to this ssid
set infrastructure ssid
multiple bssid
set data beacon rate
enable ip redirection on this ssid
第7题:
service
to-zone
attacks
port
destination-address
第8题:
mode
preshared key
external interface
security proposals
dead peer detection settings
第9题:
IKE gateway
secure tunnel interface
security policy to permit the IKE traffic
security policy referencing the IPsec VPN tunnel
第10题:
protocol
source-address
port
application
attacks
第11题:
MRU
connection speed
authentication protocol
anti-replay detection
第12题:
isolated
protected
private
associated
promiscuous
munity
第13题:

A. The peer group shortens the EBGP configuration
B. The peer group shortens the IBGP configuration
C. All the configured neighbors are in autonomous system 100
D. Three AS - path filters are applied to each BGP neighbor
E. Only the outgoing filters are applied to BGP updates
第14题:
Which two parameters are configured in IPsec policy?()
第15题:
You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users.Which two parameters must you configure on the SRX210?()
第16题:
Which two parameters are configured in IPsec policy? ()(Choose two.)
第17题:
hostname
loopback address
default gateway
domain name
SSH peer address
第18题:
Message Integrity
Compression
Authentication
Encryption
Error Detection
第19题:
mode
IKE gateway
security proposal
Perfect Forward Secrecy
第20题:
mode
IKE gateway
security proposal
Perfect Forward Secrecy
第21题:
A custom application security policy can be configured in the Advanced Firewall Security Configuration dialog box.
An optional DMZ interface can be specified in the Advanced Firewall Interface Configuration dialog box.
Custom application policies for e-mail, instant messaging, HTTP, and peer-to-peer services can be created using the Intermediate Firewall wizard.
Only the outside (untrusted) interface is specified in the Basic Firewall Interface Configuration dialog box.
The outside interface that SDM can be launched from is configured in the Configuring Firewall for Remote Access dialog box.
The SDM provides a basic, intermediate, and advanced firewall wizard.
第22题:
IPSec
IPSec with GRE
DMVPN
EZVPN
all of the choices
第23题:
secure tunnel interface
security policy to permit the IKE traffic
a route for the tunneled transit traffic
tunnel policy for transit traffic referencing the IPsec VPN