A route-based VPN generally uses less resources than a policy-based VPN.
A route-based VPN cannot have a deny action in a policy; a policy-based VPN can have a deny action.
A route-based VPN is better suited for dialup or remote access compared to a policy-based VPN.
A route-based VPN uses a policy referencing the IPsec VPN; a policy-based VPN policy does not use apolicy referencing the IPsec VPN
第1题:
Policy-based routing allows network administrators to implement routing policies to allow or deny paths based on all of these factors except which one?()
第2题:
Which two configuration elements are required for a policy-based VPN?()
第3题:
Which command is needed to change this policy to a tunnel policy for a policy-based VPN?() [edit security policies from-zone trust to-zone untrust] user@host# show policy tunnel-traffic { match { source-address local-net; destination-address remote-net; application any; then { permit; } }
第4题:
Regarding secure tunnel (st) interfaces, which statement is true?()
第5题:
A route-based VPN is required for which scenario?()
第6题:
Your company has users who connect remotely to the main office through a Windows Server 2008 VPN server.You need to ensure that users cannot access the VPN server remotely from 22:00 to 05:00. What should you do?()
第7题:
End system
Protocol
Application
Throughput
第8题:
when the remote VPN peer is behind a NAT device
when multiple networks need to be reached across the tunnel
when the remote VPN peer is a dialup or remote access client
when a dynamic routing protocol such as OSPF is required across the VPN
第9题:
Cisco IOS IPsec/SSL VPN client
Cisco VPN Clinet
ISDN terminal adapter
Cisco Adaptive Security Appliance
第10题:
A route-based VPN generally uses less resources than a policy-based VPN.
A route-based VPN cannot have a deny action in a policy; a policy-based VPN can have a deny action.
A route-based VPN is better suited for dialup or remote access compared to a policy-based VPN.
A route-based VPN uses a policy referencing the IPsec VPN; a policy-based VPN policy does not use apolicy referencing the IPsec VPN
第11题:
when the remote VPN peer is behind a NAT device
when multiple networks need to be reached across the tunnel and GRE cannot be used
when the remote VPN peer is a dialup or remote access client
when a dynamic routing protocol is required across the VPN and GRE cannot be used
第12题:
secure tunnel interface
security policy to permit the IKE traffic
a route for the tunneled transit traffic
tunnel policy for transit traffic referencing the IPsec VPN
第13题:
A route-based VPN is required for which scenario? ()
第14题:
A policy-based IPsec VPN is ideal for which scenario?()
第15题:
Regarding a route-based versus policy-based IPsec VPN, which statement is true?()
第16题:
Which statement is true regarding IPsec VPNs?()
第17题:
Which two configuration elements are required for a route-based VPN?()
第18题:
Create a network policy for VPN connections. modify the Day and time restrictions.
Create a network policy for VPN connections. apply an ip filter to deny access to the corporate network.
Modify the Logon hours for all users objects to specify only the VPN server otn he computer restrictions option
Modify the Logon hours for the default domain policy to enable the Force logoff when logon hours expire option.
第19题:
when you want to conserve tunnel resources
when the remote peer is a dialup or remote access client
when you want to configure a tunnel policy with an action of deny
when a dynamic routing protocol such as OSPF must be sent across the VPN
第20题:
set policy tunnel-traffic then tunnel remote-vpn
set policy tunnel-traffic then permit tunnel remote-vpn
set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn permit
set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
第21题:
set policy tunnel-traffic then tunnel remote-vpn
set policy tunnel-traffic then permit tunnel remote-vpn
set policy tunnel-traffic then tunnel ipsec-vpn remote-vpn permit
set policy tunnel-traffic then permit tunnel ipsec-vpn remote-vpn
第22题:
There are five phases of IKE negotiation.
There are two phases of IKE negotiation.
IPsec VPN tunnels are not supported on SRX Series devices.
IPsec VPNs require a tunnel PIC in SRX Series devices.
第23题:
QoS can be enabled on interfaces used for Easy VPN clients
QoS can be enabled on IPsec VPN interfaces and tunnels
QoS can be enabled on interfaces with an existing QoS policy
the QoS policy can be enabled for incoming and outgoing traffic on the interface
第24题:
You cannot assign st interfaces to a security zone.
You cannot apply static NAT on an st interface logical unit.
st interfaces are optional when configuring a route-based VPN
A static route can reference the st interface logical unit as the next-hop