Whichtwoconfigurationelementsarerequiredforapolicy-basedVPN?()
A. IKEgateway
B. securetunnelinterface
C. securitypolicytopermittheIKEtraffic
D. securitypolicyreferencingtheIPsecVPNtunnel
查看答案
WhichtypeofsourceNATisconfiguredintheexhibit?()[editsecuritynatsource]user@hostshowrule-set1{frominterfacege-0/0/2.0;tozoneuntrust;rule1A{match{destination-address1.1.70.0/24;}then{source-natinterface;}}}
A. interface-basedsourceNAT
B. staticsourceNAT
C. pool-basedsourceNATwithPAT
D. pool-basedsourceNATwithoutPAT
Apolicy-basedIPsecVPNisidealforwhichscenario?()
A. whenyouwanttoconservetunnelresources
B. whentheremotepeerisadialuporremoteaccessclient
C. whenyouwanttoconfigureatunnelpolicywithanactionofdeny
D. whenadynamicroutingprotocolsuchasOSPFmustbesentacrosstheVPN
WhatisaredundancygroupinJUNOSSoftware?()
A. asetofchassisclustersthatfailoverasagroup
B. asetofdevicesthatparticipateinachassiscluster
C. asetofVRRPneighborsthatfailoverasagroup
D. asetofchassisclusterobjectsthatfailoverasagroup
Giventheconfigurationshownintheexhibit,whichstatementistrueabouttrafficfromhost_atohost_b?()[editsecuritypoliciesfrom-zoneHRto-zonetrust]user@hostshowpolicytwo{match{source-addresssubnet_a;destination-addresshost_b;application[junos-telnetjunos-ping];}then{reject;}}policyone{match{source-addresshost_a;destination-addresssubnet_b;applicationany;}then{permit;}}host_aisinsubnet_aandhost_bisinsubnet_b.
A. DNStrafficisdenied.
B. Telnettrafficisdenied.
C. SMTPtrafficisdenied.
D. Pingtrafficispermitted