IKE SA is bidirectional.
IPsec SA is bidirectional.
IKE SA is established during phase 2 negotiations.
IPsec SA is established during phase 2 negotiations.
第1题:
A. mode
B. IKE gateway
C. security proposal
D. Perfect Forward Secrecy
第2题:
第3题:
A. Traffic is permitted from the trust zone to the untrust zone.
B. Intrazone traffic in the trust zone is permitted.
C. All traffic through the device is denied.
D. The policy is matched only when no other matching policies are found.
第4题:
Which two parameters are configured in IPsec policy?()
第5题:
Which two statements regarding firewall user authentication client groups are true?() (Choose two.)
第6题:
A. high scalability
B. the design supports a layered security model
C. firewall addressing does not need to change
D. IPsec decrypted traffic is inspected by the firewall
E. there is a centralized point for logging and content inspection
第7题:
Which of the following commands will display a router’s crypto map IPsec security associationsettings?()
第8题:
A. There are five phases of IKE negotiation.
B. There are two phases of IKE negotiation.
C. IPsec VPN tunnels are not supported on SRX Series devices.
D. IPsec VPNs require a tunnel PIC in SRX Series devices.
第9题:
IPSec VPN is a widely-acknowledged solution for enterprise network. Which three IPsec VPNstatements are true?()
第10题:
Which two configuration elements are required for a policy-based VPN?()