Zusammenfassung der Ressource
Frage 1
Frage
Protocol RFC 2409 (__V1) RFC 4305 (__V2)
NAT IP protocol 17: UDP port 500 (UDP 4500 for rekey, quick mode. mode-cfg)
No NAT IP protocol 17: UDP port 500
Frage 2
Frage
Protocol RFC 4303
NAT IP protocol 17: UDP port 4500
No NAT IP protocol 50
Frage 3
Antworten
-
Internet Key Exchange
-
Internet Key Extend
-
Internet Key Expert
Frage 4
Antworten
-
Authentication Header
-
Authentication Helpers
Frage 5
Frage 6
Frage
is used to authenticate peers, exchange keys, and negotiate the encryption and checksums that will be used; essentially, it is the control channel.
Frage 7
Frage
contains the authentieetion header—the checksums that verify the integrity of the data.
Frage 8
Frage
is the encapsulated security payload—the encrypted payload, essentially, the data channel.
Frage 9
Frage
Authentication Header (AH) does not offer encryption. So AH is not used by Fortigate.
Frage 10
Frage
IPsec provides services at the:
Antworten
-
Network layer
-
Transport layer
-
Session layer
-
Data link layer
Frage 11
Frage
IPsec can operate in two modes:
Frage 12
Frage
directly encapsulates and protects the fourth layer (transport) and above. The original IP header is not protected and no additional lP header is added.
Antworten
-
Transport mode
-
Tunnel mode
Frage 13
Frage
is a true tunnel. The whole lP packet is encapsulated and a new IP header is added at the beginning. After the lPsec packet reaches the remote LAN, and is unwrapped, the original packet can continue on its journey.
Antworten
-
Tunnel mode
-
Transport mode
Frage 14
Antworten
-
Security Association
-
System Association
-
Security Access
Frage 15
Frage 16
Frage
In which encapsulation mode is the original IP header protected?
Antworten
-
A. Tunnel mode
-
B. Transport mode
Frage 17
Frage
Which encapsulation mode is used for end—to-end (or client-to-client) VPNS?
Antworten
-
Tunnel mode
-
Transport mode