A. The crypto isakmp configuration is not correct.
B. The crypto map configuration is not correct.
C. The interface tunnel configuration is not correct.
D. The network configuration is not correct; netw ork 172.16.1.0 is missing.
第1题:
A. IPSec in tunnel mode
B. IPSec in transport mode
C. GRE with IPSec in transport mode
D. GRE with IPSec in tunnel mode
第2题:
Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, and into the core of an Enterprise network. The branch also allows local hosts to communicate directly with public sites in th e Internet over this same DSL connection. Which of the following answers defines how the branch NAT config avoids performing NAT for the Enterprise directed traffic but does perform NAT for the Internet - directed traffic?()
第3题:
You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()
第4题:
在GRE Tunnel接口视图下,配置隧道封装模式为GRE的完整命令为()。
第5题:
You want to dynamically assign users to an 802.1Q VLAN as a result of their authentication. Inorder to accomplish this, which two IETF RADIUS attributes should you configure on the Cisco Secure ACS?()
第6题:
You need to configure ISA3 in Seattle to enable communication with the network in New York.What should you do?()
第7题:
allows dynamic routing over the tunnel
supports multi-protocol (non-IP) traffic over the tunnel
reduces IPsec headers overhead since tunnel mode is used
simplifies the ACL used in the crypto map
uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration
第8题:
L2F tunnel
L2TP tunnel
GRE tunnel
ISAKMP tunnel
第9题:
access profile
IKE parameters
tunneled interface
redirect policy
第10题:
The crypto ACL number
The IPSEC mode (tunnel or transport)
The GRE tunnel interface IP address
The GRE tunnel source interface or IP address, and tunnel destination IP address
The MTU size of the GRE tunnel interface
第11题:
tunnel source
tunnel destination
tunnel mode
All these commands are requireD
第12题:
By not enabling NAT on the I Psec tunnel interface
By not enabling NAT on the GRE tunnel interface
By configuring the NAT - referenced ACL to not permit the Enterprise traffic
By asking the ISP to perform NAT in the cloud
第13题:
You work as a network engineer, do you know an IPsec tunnel is negotiated within the protection of whichtype of tunnel?()
第14题:
Which two mechanisms can be used to detect IPsec GRE tunnel failures?()
第15题:
An engineer is reviewing another engineer's sample configuration for a GRE tunnel used to pass IPv6 traffiC. The tunnel ha s not yet been configured on the router. Which of the following commands is not required for the configuration to pass IPv6 traffic?()
第16题:
The following configuration exists on a router on one end of an IPv6 tunnel. Although the configuration added so far is correct, the configuration is incomplete. Which type of tunnel is most likely to be intended by the network engineer?() interface loopback 1 ip address 192.168.1.1 255.255.255.255 interface tunnel 2 ipv6 address 2002:C0A8:10 1::1/64 tunnel source loopback 1
第17题:
To securely transport EIGRP traffic, a network administrator will build VPNs between sites. What is the best method to accomplish the transport of EIGRP traffic?()
第18题:
IPSec in tunnel mode
IPSec in transport mode
GRE with IPSec in transport mode
GRE with IPSec in tunnel mode
第19题:
Twenty bytes of header will be replaced with five bytes.
If the IPSec transform set includes Authentication Header, the receiving IPSec peer will discard the packets.
The IPSec packets will be dropped by Router A's compression logic.
The voice packets will not be compressed.
第20题:
when you want to conserve tunnel resources
when the remote peer is a dialup or remote access client
when you want to configure a tunnel policy with an action of deny
when a dynamic routing protocol such as OSPF must be sent across the VPN
第21题:
Automatic 6to4
Manually configured tunnel
ISATAP
GRE
第22题:
When the packet received on the LAN interface is permitted by the ACL listed on the tunnel greacl command under the incoming interface
When routing the packet, matching a route whose outgoing interface is the GRE tunnel interface
When routing the packet, matching a route whose outgoing interface is the IPsec tunnel interface
When permitted by an ACL that was referenced in the associated crypto map
第23题:
Dead Peer Detection (DPD)
CDP
isakmp keepalives
GRE keepalive mechanism
The hello mechanism of the routing protocol across the IPsec tunnel