Which two parameters are configured in IPsec policy? (Choose two.)
A. mode
B. IKE gateway
C. security proposal
D. Perfect Forward Secrecy
3 Comments on “Which two parameters are configured in IPsec policy?”
ketan2809says:
1.A proposal for IKE Phase 2: Recall that this step is
optional because you can use the Junos predefined
proposals (the choices are basic, compatible, or
standard). We named the configured proposal
ike-phase2-proposal. We decided to use
authentication algorithm hmac-md5-96, encryption
algorithm 3des-cbc, and the ESP protocol.
2. A policy called ipsec-pol1: Within the policy we
referred to the proposal ike-phase2-proposal, and
we specified that IPsec will use DH Group 2 as its PFS.
3. A VPN tunnel, called TunnelA: Within the tunnel we
referred to the gateway ike-phase1-gateway and
the IKE Phase 2 policy ipsec-pol1. We also specified
that tunnels should establish immediately.
0
0
ketan2809says:
Answer: C D
0
0
Shaun Lanesays:
JN0-332 exam End of Life (EOL) on July 1, 2017, the new exam is JN0-333.
1.A proposal for IKE Phase 2: Recall that this step is
optional because you can use the Junos predefined
proposals (the choices are basic, compatible, or
standard). We named the configured proposal
ike-phase2-proposal. We decided to use
authentication algorithm hmac-md5-96, encryption
algorithm 3des-cbc, and the ESP protocol.
2. A policy called ipsec-pol1: Within the policy we
referred to the proposal ike-phase2-proposal, and
we specified that IPsec will use DH Group 2 as its PFS.
3. A VPN tunnel, called TunnelA: Within the tunnel we
referred to the gateway ike-phase1-gateway and
the IKE Phase 2 policy ipsec-pol1. We also specified
that tunnels should establish immediately.
0
0
Answer: C D
0
0
JN0-332 exam End of Life (EOL) on July 1, 2017, the new exam is JN0-333.
The newest JN0-333 dumps are available here FYI:
https://drive.google.com/open?id=0B-ob6L_QjGLpNzNvWWE1ck01MHM
Best Regards!!!
0
0