Refer to the exhibit. A new TAC engineer came to you for advice. A GRE over IPsec tunnel was configured, but the tunnel is not coming up. W hat did the TAC engineer configure incorrectly?()A. The crypto isakmp configuration is not correct.B. The crypto ma

题目
Refer to the exhibit. A new TAC engineer came to you for advice. A GRE over IPsec tunnel was configured, but the tunnel is not coming up. W hat did the TAC engineer configure incorrectly?()

A. The crypto isakmp configuration is not correct.

B. The crypto map configuration is not correct.

C. The interface tunnel configuration is not correct.

D. The network configuration is not correct; netw ork 172.16.1.0 is missing.


相似考题
更多“Refer to the exhibit. A new TAC engineer came to you for advice. A GRE over IPsec tunnel was configured, but the tunnel is not coming up. W hat did the TAC engineer configure incorrectly?() ”相关问题
  • 第1题:

    To securely transport EIGRP traffic, a network administrator will build VPNs between sites. What is the best method to accomplish the transport of EIGRP traffic?()

    A. IPSec in tunnel mode

    B. IPSec in transport mode

    C. GRE with IPSec in transport mode

    D. GRE with IPSec in tunnel mode


    参考答案:C

  • 第2题:

    Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, and into the core of an Enterprise network. The branch also allows local hosts to communicate directly with public sites in th e Internet over this same DSL connection. Which of the following answers defines how the branch NAT config avoids performing NAT for the Enterprise directed traffic but does perform NAT for the Internet - directed traffic?()

    • A、By not enabling NAT on the I Psec tunnel interface
    • B、By not enabling NAT on the GRE tunnel interface
    • C、By configuring the NAT - referenced ACL to not permit the Enterprise traffic
    • D、By asking the ISP to perform NAT in the cloud

    正确答案:C

  • 第3题:

    You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()

    • A、The crypto ACL number
    • B、The IPSEC mode (tunnel or transport)
    • C、The GRE tunnel interface IP address
    • D、The GRE tunnel source interface or IP address, and tunnel destination IP address
    • E、The MTU size of the GRE tunnel interface

    正确答案:C,D

  • 第4题:

    在GRE Tunnel接口视图下,配置隧道封装模式为GRE的完整命令为()。

    • A、tunnel protocol gre
    • B、tunnel gre
    • C、tunnel-protocol gre
    • D、protocol gre

    正确答案:C

  • 第5题:

    You want to dynamically assign users to an 802.1Q VLAN as a result of their authentication.  Inorder to accomplish this, which two IETF RADIUS attributes should you configure on the Cisco Secure ACS?()

    • A、083 Tunnel-Preference
    • B、066 Tunnel-Client-Endpoint
    • C、064 Tunnel-Type
    • D、082 Tunnel-Assignment-ID
    • E、081 Tunnel-Private-Group-ID
    • F、067 Tunnel-Server-Endpoint

    正确答案:C,E

  • 第6题:

    You need to configure ISA3 in Seattle to enable communication with the network in New York.What should you do?()

    • A、Open the ports for DNS, HTTP, HTTPS, Kerberos, RADIUS, LDAP, RPC endpoint mapper and client, and Server Message Block (SMB) over IP
    • B、Enable the Routing and Remote Access Basic Firewall. Open the ports for DNS, Kerberos, LDAP, Exchange RPCs, RADIUS, L2TP, and Internet Key Exchange (IKE)
    • C、Create a PPTP tunnel from ISA3 to the New York network
    • D、Create an L2TP/IPSec tunnel from ISA3 to the New York network

    正确答案:D

  • 第7题:

    多选题
    Which three features are benefits of using GRE tunnels in conjunction with IPsec for building site-to-site VPNs?()
    A

    allows dynamic routing over the tunnel

    B

    supports multi-protocol (non-IP) traffic over the tunnel

    C

    reduces IPsec headers overhead since tunnel mode is used

    D

    simplifies the ACL used in the crypto map

    E

    uses Virtual Tunnel Interface (VTI) to simplify the IPsec VPN configuration


    正确答案: C,B
    解析: 暂无解析

  • 第8题:

    单选题
    You work as a network engineer, do you know an IPsec tunnel is negotiated within the protection of whichtype of tunnel?()
    A

    L2F tunnel

    B

    L2TP tunnel

    C

    GRE tunnel

    D

    ISAKMP tunnel


    正确答案: D
    解析: 暂无解析

  • 第9题:

    多选题
    You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users.Which two parameters must you configure on the SRX210?()
    A

    access profile

    B

    IKE parameters

    C

    tunneled interface

    D

    redirect policy


    正确答案: B,A
    解析: 暂无解析

  • 第10题:

    多选题
    You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()
    A

    The crypto ACL number

    B

    The IPSEC mode (tunnel or transport)

    C

    The GRE tunnel interface IP address

    D

    The GRE tunnel source interface or IP address, and tunnel destination IP address

    E

    The MTU size of the GRE tunnel interface


    正确答案: C,E
    解析: 暂无解析

  • 第11题:

    单选题
    An engineer is reviewing another engineer's sample configuration for a GRE tunnel used to pass IPv6 traffiC. The tunnel ha s not yet been configured on the router. Which of the following commands is not required for the configuration to pass IPv6 traffic?()
    A

    tunnel source

    B

    tunnel destination

    C

    tunnel mode

    D

    All these commands are requireD


    正确答案: D
    解析: 暂无解析

  • 第12题:

    单选题
    Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, and into the core of an Enterprise network. The branch also allows local hosts to communicate directly with public sites in th e Internet over this same DSL connection. Which of the following answers defines how the branch NAT config avoids performing NAT for the Enterprise directed traffic but does perform NAT for the Internet - directed traffic?()
    A

    By not enabling NAT on the I Psec tunnel interface

    B

    By not enabling NAT on the GRE tunnel interface

    C

    By configuring the NAT - referenced ACL to not permit the Enterprise traffic

    D

    By asking the ISP to perform NAT in the cloud


    正确答案: C
    解析: 暂无解析

  • 第13题:

    You work as a network engineer, do you know an IPsec tunnel is negotiated within the protection of whichtype of tunnel?()

    • A、L2F tunnel
    • B、L2TP tunnel
    • C、GRE tunnel
    • D、ISAKMP tunnel

    正确答案:D

  • 第14题:

    Which two mechanisms can be used to detect IPsec GRE tunnel failures?()

    • A、Dead Peer Detection (DPD)
    • B、CDP
    • C、isakmp keepalives
    • D、GRE keepalive mechanism
    • E、The hello mechanism of the routing protocol across the IPsec tunnel

    正确答案:A,E

  • 第15题:

    An engineer is reviewing another engineer's sample configuration for a GRE tunnel used to pass IPv6 traffiC. The tunnel ha s not yet been configured on the router. Which of the following commands is not required for the configuration to pass IPv6 traffic?()

    • A、tunnel source
    • B、tunnel destination
    • C、tunnel mode
    • D、All these commands are requireD

    正确答案:C

  • 第16题:

    The following configuration exists on a router on one end of an IPv6 tunnel. Although the configuration added so far is correct, the configuration is incomplete. Which type of tunnel is most likely to be intended by the network engineer?() interface loopback 1 ip address 192.168.1.1 255.255.255.255 interface tunnel 2 ipv6 address 2002:C0A8:10 1::1/64 tunnel source loopback 1

    • A、Automatic 6to4
    • B、Manually configured tunnel
    • C、ISATAP
    • D、GRE

    正确答案:A

  • 第17题:

    To securely transport EIGRP traffic, a network administrator will build VPNs between sites. What is the best method to accomplish the transport of EIGRP traffic?()

    • A、IPSec in tunnel mode
    • B、IPSec in transport mode
    • C、GRE with IPSec in transport mode
    • D、GRE with IPSec in tunnel mode

    正确答案:C

  • 第18题:

    单选题
    To securely transport EIGRP traffic, a network administrator will build VPNs between sites. Whatis the best method to accomplish the transport of EIGRP traffic?()
    A

     IPSec in tunnel mode

    B

     IPSec in transport mode

    C

     GRE with IPSec in transport mode

    D

     GRE with IPSec in tunnel mode


    正确答案: C
    解析: 暂无解析

  • 第19题:

    单选题
    Refer to the exhibit. With an IPSec tunnel established between remote Router A and head-end router B, with Compressed Real-Time Protocol (cRTP) configured on the serial interface of Router A, what impact will the cRTP configuration have on the Voice over IP packets flowing through the IPSec tunnel from a Cisco 7960 IP phone?()
    A

    Twenty bytes of header will be replaced with five bytes. 

    B

    If the IPSec transform set includes Authentication Header, the receiving IPSec peer will discard the packets. 

    C

    The IPSec packets will be dropped by Router A's compression logic.

    D

    The voice packets will not be compressed.


    正确答案: B
    解析: 暂无解析

  • 第20题:

    单选题
    A policy-based IPsec VPN is ideal for which scenario?()
    A

    when you want to conserve tunnel resources

    B

    when the remote peer is a dialup or remote access client

    C

    when you want to configure a tunnel policy with an action of deny

    D

    when a dynamic routing protocol such as OSPF must be sent across the VPN


    正确答案: B
    解析: 暂无解析

  • 第21题:

    单选题
    The following configuration exists on a router on one end of an IPv6 tunnel. Although the configuration added so far is correct, the configuration is incomplete. Which type of tunnel is most likely to be intended by the network engineer?() interface loopback 1 ip address 192.168.1.1 255.255.255.255 interface tunnel 2 ipv6 address 2002:C0A8:10 1::1/64 tunnel source loopback 1
    A

    Automatic 6to4

    B

    Manually configured tunnel

    C

    ISATAP

    D

    GRE


    正确答案: B
    解析: 暂无解析

  • 第22题:

    单选题
    Router R1, a branch router, connects to the Internet using DSL. Some traffic flows through a GRE and IPsec tunnel, over the DSL connection, destined for an Enterprise network. Which of the following answers best describes the router's logic that tells the router, for a given packet, to apply GRE encapsulation to the packet?()
    A

    When the packet received on the LAN interface is permitted by the ACL listed on the tunnel greacl command under the incoming interface

    B

    When routing the packet, matching a route whose outgoing interface is the GRE tunnel interface

    C

    When routing the packet, matching a route whose outgoing interface is the IPsec tunnel interface

    D

    When permitted by an ACL that was referenced in the associated crypto map


    正确答案: D
    解析: 暂无解析

  • 第23题:

    多选题
    Which two mechanisms can be used to detect IPsec GRE tunnel failures?()
    A

    Dead Peer Detection (DPD)

    B

    CDP

    C

    isakmp keepalives

    D

    GRE keepalive mechanism

    E

    The hello mechanism of the routing protocol across the IPsec tunnel


    正确答案: B,D
    解析: 暂无解析