多选题An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)AOnly main mode can be used for IKE negotiationBA local-identity must be definedCIt must be t

题目
多选题
An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)
A

Only main mode can be used for IKE negotiation

B

A local-identity must be defined

C

It must be the initiator for IKE

D

A remote-identity must be defined

参考答案和解析
正确答案: B,C
解析: 暂无解析
如果没有搜索结果或未解决您的问题,请直接 联系老师 获取答案。
相似问题和答案

第1题:

Which statement is true regarding IPsec VPNs?()

A. There are five phases of IKE negotiation.

B. There are two phases of IKE negotiation.

C. IPsec VPN tunnels are not supported on SRX Series devices.

D. IPsec VPNs require a tunnel PIC in SRX Series devices.


参考答案:D

第2题:

What are two requirements when using Packet Flow Acceleration? ()(Choose two.)

A. Traffic needs be compressed.

B. Quality of service must be enabled.

C. A service tunnel must exist in at least one direction.

D. PFA must be enabled on the client-side WX device.


参考答案:A, B

第3题:

Click the Exhibit button.System services SSH, Telnet, FTP, and HTTP are enabled on the SRX Series device.Referring to the configuration shown in the exhibit, which two statements are true? ()(Choose two.)

A. A user can use SSH to interface ge-0/0/0.0 and ge-0/0/1.0.

B. A user can use FTP to interface ge-0/0/0.0 and ge-0/0/1.0.

C. A user can use SSH to interface ge-0/0/0.0.

D. A user can use SSH to interface ge-0/0/1.0.


参考答案:B, C

第4题:

You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users.Which two parameters must you configure on the SRX210?()

  • A、access profile
  • B、IKE parameters
  • C、tunneled interface
  • D、redirect policy

正确答案:A,B

第5题:

You need to configure a GRE tunnel on a IPSec router. When you are using the SDM to configurea GRE tunnel over IPsec, which two parameters are required when defining the tunnel interfaceinformation?()

  • A、The crypto ACL number
  • B、The IPSEC mode (tunnel or transport)
  • C、The GRE tunnel interface IP address
  • D、The GRE tunnel source interface or IP address, and tunnel destination IP address
  • E、The MTU size of the GRE tunnel interface

正确答案:C,D

第6题:

An IPsec tunnel is established on an SRX Series Gateway on an interface whose IP address was obtained using DHCP.Which two statements are true? ()(Choose two.)

A. Only main mode can be used for IKE negotiation

B. A local-identity must be defined

C. It must be the initiator for IKE

D. A remote-identity must be defined


参考答案:B, C

第7题:

Which three statements about the Cisco MPLS TE Fast Reroute (FRR) process are true?()

  • A、TE tunnels that are configured with the FRR option cannot be used as backup tunnels.
  • B、TE tunnels that are configured with the FRR option can be used as backup tunnels.
  • C、The backup tunnel that is used to protect a physical interface must have a valid IP address configured.
  • D、Interfaces must use MPLS global label allocation.
  • E、The source IP address of use backup tunnel and the merge point (MP) should not be reachable.

正确答案:A,C,D

第8题:

You are configuring an SRX210 as a firewall enforcer that will tunnel IPsec traffic from several Junos Pulse users.Which two parameters must you configure on the SRX210?()

A. access profile

B. IKE parameters

C. tunneled interface

D. redirect policy


参考答案:A, B

第9题:

Which two statements are true about overflow pools?()

  • A、Overflow pools do not support PAT
  • B、Overflow pools can not use the egress interface IP address for NAT
  • C、Overflow pools must use PAT
  • D、Overflow pools can contain the egress interface IP address or separate IP addresses

正确答案:C,D

第10题:

You are installing a MAG Series device for access control using an SRX Series device as the firewall enforcer. The MAG Series device resides in the same security zone as users. However, the users reside in different subnets and use the SRX Series device as an IP gateway.Which statement is true?()

  • A、You must configure a security policy on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
  • B、No security policy is necessary on the SRX Series device to allow traffic to flow from the user devices to the MAG Series device.
  • C、You must configure host-inbound traffic on the SRX Series device to allow SSL traffic between the MAG Series device and the user devices.
  • D、You must configure host-inbound traffic on the SRX Series device to allow EAP traffic between the MAG Series device and the user devices.

正确答案:A

更多相关问题