353¡¢°ü¹ýÂË·À»ðǽÔÚÓ¦Óòã¶Ôÿһ¸öÊý¾Ý°ü½øÐмì²é£¬¸ù¾ÝÅäÖõݲȫ²ßÂÔת·¢»ò¶ªÆúÊý¾Ý°ü¡£--------------------------------------F
354¡¢´úÀí·À»ðǽ×÷ÓÃÓÚTCP/IPÐÒéÕ»µÄ´«Êä²ã£¬ÊµÖÊÊÇ´úÀí·À»ðǽ´úÀí´¦ÀíÄÚ²¿ÍøÂçºÍÍâ²¿ÍøÂçÓû§Ö®¼äµÄÒµÎñ¡£-------------------F
355¡¢add-group { number 1 name } no-pat ÖÐno-pat ²ÎÊýµÄº¬ÒåÊÇ:
A¡¢²»×öµØÖ·×ª»» B¡¢½øÐж˿ڸ´Óà C¡¢²»×ª»»Ô´¶Ë¿Ú D¡¢²»×ª»»Ä¿µÄ¶Ë¿Ú
356¡¢ÐÅÏ¢¼ÓÃܵÄËĸö¹Ø¼üÒªËØ£ºÃ÷ÎÄ¡¢ÃÜÎÄ¡¢¼ÓÃÜËã·¨ºÍÃÜÔ¿£¬ÎªÁËÈ·±£ÐÅÏ¢µÄ±£ÃÜÐÔ£¬Ðè¶Ô¼ÓÃÜËã·¨½øÐб£ÃÜ¡£------------------------------F 357¡¢IP SecÖÐÒÔÏÂÄĸöËã·¨²»ÊôÓÚ¼ÓÃÜËã·¨:
A¡¢DES B¡¢SHA1 C¡¢3DES D¡¢AES
358¡¢USG²úÆ·Îļþ¹²Ïí¼¼Êõ¾ÍÊǽ«Îļþ¹²ÏíÐÒéת»»³É»ùÓÚSSL³¬Îı¾´«ÊäÐÒé(Https)£¬Õë¶ÔÖÕ¶ËÓû§¸Ð¾õÎļþ·þÎñÆ÷¾ÍÊÇ»ùÓÚWebÓ¦Óá£----------------------------T
359¡¢USGϵÁзÀ»ðǽĬÈϵİ²È«ÇøÓò²»ÄÜɾ³ý£¬µ«¿ÉÒÔÐÞ¸ÄÆä°²È«¼¶±ð¡£---------------------------------F
360¡¢ÏÂÃæÃèÊöÊÇSSLÎÕÊÖÐÒé¸÷½×¶ÎÖеÄÄÚÈÝÓÐÄÄЩ?£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢¿Í»§¶Ë·¢ËÍclient_HelloÏûÏ¢£¬·þÎñÆ÷¶Ë»ØÓ¦Server HelloÏûÏ¢ B¡¢·þÎñÆ÷¶Ë·¢ËÍServer Hello±ãµÈ´ý¿Í»§¶Ë·¢Ë͵ÄÏûÏ¢
C¡¢¿Í»§¶ËÊÕµ½·þÎñÆ÷·¢Ë͵ÄһϵÁÐÏûÏ¢²¢Ïû»¯ºó£¬·¢ËÍClient Key ExchangeµÈÏûÏ¢¸ø·þÎñÆ÷
D¡¢¿Í»§¶ËºÍ·þÎñÆ÷¸÷×Ô·¢ËÍChangeCipherSpecºÍfinishedÏûÏ¢¸ø¶Ô·½ 361¡¢Policy Center×¼Èë¿ØÖÆ¿ÉÖ§³ÖÒÔÏÂÄÄЩ:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢Ó²¼þSACG(Ó²¼þ°²È«½ÓÈë¿ØÖÆÍø¹Ø) B¡¢802.1X C¡¢ARP¿ØÖÆ
D¡¢Èí¼þSACG(Ö÷»ú·À»ðǽ) 362¡¢USG²úÆ·ÅäÖÃʱ£¬VPNDBÖеÄÓû§ÐÅÏ¢¿ÉÒÔµ¥¸ö´´½¨£¬Ò²¿ÉÒÔͨ¹ýµ¼ÈëÎļþÅúÀï´´½¨¡£------------------------------------T
363¡¢SSL VPNÖ§ÌØÎļþ¹²ÏíÀàÐÍ·ÖΪSMBºÍNFSÁ½ÖÖ£¬SMB¶ÔÓ¦windowsÖ÷»ú£¬NFS¶ÔÓ¦LinuxÖ÷»ú¡£--------------------------------T
364¡¢»ùÓÚOutbound·½ÏòNATÅäÖã¬ÔÚÓÐno-patÅäÖòÎÊýµÄÇé¿öÏ£¬ÒÔÏÂÄÄЩ˵Ã÷ÊÇ´íÎóµÄ:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢Ö»½øÐÐÔ´IPµØÖ·×ª»» B¡¢Ö»½øÐÐÄ¿µÄIPµØÖ·×ª»» C¡¢½øÐÐÔ´IPµØÖ·ºÍÔ´¶Ë¿Úת»»
D¡¢½øÐÐÄ¿µÄIPµØÖ·ºÍÄ¿µÄ¶Ë¿Úת»»
365¡¢Poliry Centerϵͳ֧³ÖÒÔÏÂÄÄЩÓû§ÈÏÖ¤·½Ê½:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢IPµØÖ·ÈÏÖ¤ B¡¢MACµØÖ·ÈÏÖ¤
C¡¢ÆÕͨÕ˺Å/¿ÚÁîÈÏÖ¤ D¡¢LDAPÈÏÖ¤
366¡¢ÏÂÁйØÓÚ²»Í¬ÀàÐ͵ķÀ»ðǽµÄ˵·¨ÖÐÕýÈ·µÄÓÐ:£¨Ñ¡Ôñ3¸ö´ð°¸}
A¡¢°ü¹ýÂË·À»ðǽ¶ÔÓÚͨ¹ý·À»ðǽµÄÿ¸öÊý¾Ý°ü£¬¶¼Òª½øÐÐACLÆ¥Åä¼ì²é B¡¢×´Ì¬¼ì²â·À»ðǽֻ¶ÔûÓÐÃüÖлỰµÄÊ×°ü½øÐа²È«²ßÂÔ¼ì²é
C¡¢×´Ì¬¼ì²â·À»ðǽÐèÒªÅäÖñ¨Îĵġ°È¥¡±ºÍ¡°»Ø¡±Á½¸ö·½ÏòµÄ°²È«²ßÂÔ D¡¢´úÀí·À»ðǽ´úÀíÄÚ²¿ÍøÂçºÍÍâ²¿ÍøÂçÓû§Ö®¼äµÄÒµÎñ 367¡¢¹ÜÀíÔ±´î½¨ÁËÈçÏÂ×éÍø:
LAN_A----Ò»£¨G0/0)USG_A(G0/1)----Ò»(G0/0)USG_B(G0/1)-------LAN_B
USG_A»®·ÖÁË·À»ðǽ°²È«ÇøÓò£¬Á¬½ÓLAN_AµÄÇøÓòTrust,Á¬½ÓUSG_BµÄÇøÓòÊÇUntrust¸ù¾ÝÉÏÃæµÄÃèÊö£¬ÒÔÏÂ˵·¨ÕýÈ·µÄÊÇ:
A¡¢USG_B G0/0±ØÐë¼ÓÈëUntrustÇøÓò B¡¢USG_B G0/0±ØÐë¼ÓTrustÇøÓò C¡¢USG_B G0/1±ØÐë¼ÓTrustÇøÓò D¡¢USG_B G0/0¿ÉÒÔ¼ÓÈëÈÎÒâÇøÓò
368¡¢ÔÚIKEÐÉ̵ÚÒ»½×¶ÎÖУ¬ÒÔÏÂÄĸöIKE½»»»Ä£Ê½²»ÄÜÌṩÉí·Ý±£»¤¹¦ÄÜ:
A¡¢Ö÷ģʽ B¡¢Ò°Âùģʽ C¡¢¿ìËÙģʽ D¡¢±»¶¯Ä£Ê½
369¡¢USG·À»ðǽ¸ß¼¶ACLµÄÆ¥Å䣬¿ÉÒÔͨ¹ýÔ´IPµØÖ·¡¢Ä¿µÄIPµØÖ·¡¢Ô´MACµØÖ·¡¢Ä¿µÄMACµØÖ·¡¢ÐÒéµÈά¶ÈÀ´½øÐÐÁ÷ÀïÆ¥Åä¡£------------------F
370¡¢ÏÂÁйØÓÚNATµØÖ·×ª»»µÄ˵·¨ÖÐÄÄЩÊÇÕýÈ·µÄ:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢µØÖ·×ª»»¼¼Êõ¿ÉÒÔÓÐЧÒþ²Ø¾ÖÓòÍøÄÚµÄÖ÷»ú£¬ÊÇÒ»ÖÖÓÐЧµÄÍøÂ簲ȫ±£»¤¼¼Êõ B¡¢µØÖ·×ª»»¿ÉÒÔ°´ÕÕÓû§µÄÐèÒª£¬ÔÚ¾ÖÓòÍøÄÚÏòÍâÌṩFTP¡¢WWW¡¢TelnetµÈ·þÎñ C¡¢ÓÐЩӦÓòãÐÒéÔÚÊý¾ÝÖÐЯ´øIPµØÖ·ÐÅÏ¢£¬¶ÔËüÃÇ×÷NATʱ»¹ÒªÐÞ¸ÄÉϲãÊý¾ÝÖеÄIPµØÖ·ÐÅÏ¢
D¡¢¶ÔÓÚijЩ·ÇTCP¡¢UDPµÄÐÒ飨ÈçICMP¡¢PPTP)£¬ÎÞ·¨×öNATת»»
371¡¢ÔÚUSGϵÁзÀ»ðÇ½ÇøÓò¼äʹÓÃdetectÃüÁÈôÓ¦ÓÃÐÒéΪ·Ç±ê×¼¶Ë¿Ú£¬ÒÔÏÂÄĸö¼¼Êõ¿É½â¾öÓɷDZê×¼¶Ë¿ÚËù´øÀ´µÄÎÊÌâ:
A¡¢¶Ë¿Úʶ±ð
B¡¢MACÓëIPµØÖ·°ó¶¨ C¡¢°ü¹ýÂË D¡¢³¤Á¬½Ó
372¡¢ÒÔÏÂÄÄÀà¼ÓÃÜËã·¨£¬¼ÓÃܺͽâÃܵÄÃÜÔ¿ÊÇÏàͬµÄ:
A¡¢DES
B¡¢RSA£¨1024£© C¡¢MD5 D¡¢SHA-1
373¡¢USG²úÆ·ÍøÂçÀ©Õ¹¹¦ÄÜÖУ¬ÐèҪʵÏÖÓû§¼´¿ÉÒÔ·ÃÎÊÔ¶¶ËÆóÒµÄÚÍøºÍ±¾µØ¾ÖÓòÍø£¬ÓÖÄÜ·ÃÎÊInternetÐèҪʹÓõĿͻ§¶Ë·ÓÉ·½Ê½Îª:
A¡¢È«Â·ÓÉģʽ(Full Tunnel) B¡¢·ÖÀëģʽ£¨Split Tunnel £© C¡¢Â·ÓÉģʽ(route Tunnel)
D¡¢ÊÖ¶¯Ä£Ê½(Manual Tunnel)
374¡¢Policy Centerϵͳ¿ÉÒÔʵÏÖ×éÖ¯¹ÜÀíºÍÇøÓò¹ÜÀíÁ½¸öά¶ÈµÄ¹ÜÀí¹¦ÄÜ¡£-----------------------------------------T
375¡¢ÏÂÁйØÓÚASPFºÍServer mapµÄ˵·¨ÕýÈ·µÄÊÇ:¡²Ñ¡Ôñ2¸ö´ð°¸£©
A¡¢ASPF¼ì²éÓ¦ÓòãÐÒéÐÅÏ¢²¢ÇÒ¼à¿ØÁ¬½ÓµÄÓ¦ÓòãÐÒé״̬ B¡¢ASPFͨ¹ý¶¯Ì¬µÄÉú³ÉACLÀ´¾ö¶¨Êý¾Ý°üÊÇ·ñͨ¹ý·À»ðǽ C¡¢ÅäÖÃNAT ServerÉú³ÉµÄÊǾ²Ì¬Server-map D¡¢Server-map±íÓÃÎåÔª×éÀ´±íʾһÌõ»á»°
396¡¢ USG²úÆ·¿ÉÒÔͨ¹ýÈçÏÂÄÄЩ·½Ê½¶ÔÓû§½øÐзÃÎÊȨÏÞ¿ØÖÆ:
A¡¢IP B¡¢MAC C¡¢PORT D¡¢URL
377¡¢USG²úÆ·ÒµÎñ¹¦ÄܰüÀ¨:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢Web´úÀí B¡¢ÍøÂçÀ©Õ¹ C¡¢¶Ë¿Ú¹²Ïí D¡¢Îļþ¹²Ïí
378¡¢Policy CenterϵͳµÄ¹²ÏíĿ¼¼ì²é°²È«²ßÂÔ°üÀ¨ÒÔÏÂÄÄЩ·½ÃæÄÚÈÝ:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢¹²ÏíÎļþ´óС¼ì²é£¬¶ÔÓÚ´óÎļþ²»ÔÊÐí¹²Ïí B¡¢¹²ÏíÕ˺ÅÃû³Æ(Óû§»òÕßÓû§×é)¼ì²é C¡¢Î¥¹æ¹²ÏíȨÏÞ¼ì²é
D¡¢Ìṩ×Ô¶¯ÐÞ¸´¹¦ÄÜ£¬É¾³ýÎ¥¹æ¹²Ïí
379¡¢Èç¹û·À»ðǽµÄÁ½¸ö½Ó¿ÚÁ¬½Óͬһ¸öÇøÓò£¬Á½¸ö½Ó¿ÚÊý¾Ý°üÁ÷¶¯Ò²±ØÐë¾¹ýÓò¼ä°ü¹ýÂÇ´¦Àí¡£-----------------------------------F
380¡¢VLANµÄTagÐÅÏ¢°üº¬ÔÚÄĸö±¨ÎĶÎÖÐ:
A¡¢ÒÔÌ«ÍøÖ¡Í·ÖÐ B¡¢IP±¨ÎÄÍ·ÖÐ C¡¢TCP±¨ÎÄÍ·ÖÐ D¡¢UDP±¨ÎÄÍ·ÖÐ
381¡¢ÒÔÏÂÄÄЩ¼¼Êõ¿ÉÒÔʵÏ־ܾø·Ç·¨Ö÷»ú»ò·Ç·¨Êý¾Ý±¨ÎÄͨ¹ý:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢MACÓëlPµØÖ·°ó¶¨ B¡¢ACL C¡¢ºÚÃûµ¥ D¡¢¾²Ì¬Â·ÓÉ 382¡¢IPSec°²È«ÐÒéAHºÍESPµÄÇø±ðÔÚÓÚAHÄÜʵÏÖÊý¾Ý¼ÓÃÜ£¬ESPÖ§³ÖµÄÊý¾ÝÑéÖ¤·¶Î§¸ü¹ã¡£--------------------------------------F
383¡¢ÔÚµ±Ç°ÍøÂçÖÐÒѾ²¿ÊðÁËÆäËûµÄÉí·ÝÈÏ֤ϵͳ£¬É豸ͨ¹ýÆôÓõ¥µãµÇ¼¹¦ÄÜ£¬¼õÉÙÓû§Öظ´ÊäÈëÃÜÂë¡£¹ØÓÚµ¥µãµÇ¼˵·¨ÕýÈ·µÄÊÇ:£¨Ñ¡Ôñ2¸ö´ð°¸£©
A¡¢É豸¿ÉÒÔʶ±ð³ö¾¹ýÕâЩÉí·ÝÈÏ֤ϵͳÈÏ֤ͨ¹ýµÄÓû§£¬Óû§ÉÏÍøÊ±£¬É豸½«²»ÍÆËÍÈÏÖ¤Ò³Ãæ£¬±ÜÃâÔÙ´ÎÒªÇóÊäÈëÓû§Ãû/ÃÜÂë
B¡¢É豸½öÖ§³ÖADÓòµ¥µãµÇ¼
C¡¢ËäÈ»²»ÐèÒªÊäÈëÓû§ÃÜÂ룬µ«ÊÇÈÏÖ¤·þÎñÆ÷ÐèÒª½«Óû§ÃÜÂëºÍÉ豸½øÐн»»¥£¬ÓÃÀ´±£Ö¤ÈÏ֤ͨ¹ý
D¡¢É豸֧³ÖLDAP£¬ADÓòµ¥µãµÇ¼ 384¡¢ÒÔÏÂÄĸöIKE½»»»Ä£Ê½¿ÉÒÔ²ÉÓÃIPµØÖ··½Ê½»òName·½Ê½±êʶ¶ÔµÈÌ壨ѡÔñ:2¸ö´ð°¸£©
A¡¢Ö÷ģʽ B¡¢Ò°Âùģʽ C¡¢¿ìËÙģʽ D¡¢±»¶¯Ä£Ê½
385¡¢IPµØÖ·É¨Ãèõ»÷µÄ¹¥»÷ÕßÔËÓÃICMP±¨ÎÄ̽²âÄ¿±êµØÖ·£¬»ñȡĿ±êÍøÂçµÄÍØÆË½á¹¹ºÍ´æ»îµÄϵͳ£¬ÊµÊ©ÏÂÒ»²½¹¥»÷×ö×¼±¸¡£--------------------------------T
386¡¢ÔÚUSGϵÁзÀ»ðǽϵͳÊÓͼÏ£¬Ö´ÐÐÍêÃüÁîreset saved-configurationºóÉ豸ÅäÖþͻá»Ö¸´µ½È±Ê¡ÅäÖã¬ÎÞÐè½øÐÐÆäËû²Ù×÷¼´¿ÉÉúЧ¡£---------------------------------------------F 387¡¢Policy CenterϵͳÖ÷ÒªÓÉÒÔÏÂÄÄЩ×é¼þ×é³É:(Ñ¡Ôñ3¸ö´ð°¸)
A¡¢·À²¡¶¾·þÎñÆ÷ B¡¢SC¿ØÖÆ·þÎñÆ÷ C¡¢×¼Èë¿ØÖÆÉ豸 D¡¢SM¹ÜÀí·þÎñÆ÷
388¡¢ÔÚ·À»ðǽ¼ä°²È«²ßÂÔÖУ¬inboundÊÇÖ¸Êý¾Ý°ü´ÓµÍÓÅÏȼ¶ÇøÓò·ÃÎʸßÓÅÏȼ¶ÇøÓò¡£ÔÚ·À»ðǽÓòÄÚ°²È«²ßÂÔÖУ¬Ã»ÓÐinboundºÍoutbound·½Ïò£¬Ö»ÐèÒªÖ±½Ó¶¨ÒåSourceºÍDestination¼´¿É¡£--------------------------T
389¡¢¶ÔÓÚ·À»ðǽĬÈϰ²È«ÇøÓòTrustºÍUntrustµÄ˵·¨ÕýÈ·µÄÓÐ:£¨Ñ¡Ôñ2¸ö´ð°¸£©
A¡¢TrustÇøÓò·ÃÎÊUntrustÇøÓò·½ÏòΪoutbound·½Ïò B¡¢TrustÇøÓò·ÃÎÊUntrustÇøÓò·½ÏòΪinbound·½Ïò C¡¢TrustµÄ°²È«¼¶±ðÊÇ85 D¡¢UntrustµÄ°²È«¼¶±ðÊÇ50
390¡¢IPSecµÄ±ØÐèÅäÖò½Öè°üÀ¨: £¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢ÅäÖÃIKEµÄ¼ÓÃÜËãÈαãÓÃDES B¡¢¶¨Òå±£»¤Êý¾ÝÁ÷ºÍÓò¼ä¹æÔò C¡¢½«IPSec°²È«²ßÂÔÓ¦Óõ½½Ó¿Ú D¡¢ÅäÖÃIKE Peer
391¡¢USGϵÁзÀ»ðǽ5Ôª×é°üÀ¨ÒÔÏÂÄÄЩѡÏî:£¨Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢Ô´IPµØÖ· B¡¢Ä¿µÄIPµØÖ· C¡¢ÐÒéºÅ
D¡¢Ô´MACµØÖ·
392¡¢·À»ðǽ½øÐÐAVºÍIPSµÄÅäÖÃǰÐèÒªÍê³ÉÏÂÁвÙ×÷:¡²Ñ¡Ôñ3¸ö´ð°¸£©
A¡¢ÐèÒªÉêÇë²¢¼¤»îUTMÌØÐÔµÄlicense²¢Éý¼¶ÌØÕ÷¿â B¡¢Ö¸¶¨Ê¹ÓõIJ¡¶¾¿â¡¢IPSÇ©Ãû¿â¡¢URLÈȵã¿âºÍ֪ʶ¿â C¡¢È·ÈÏ·À»ðǽģʽΪUTMģʽ£¬ÆôÓÃUTM D¡¢¹Ø±Õ·À»ðǽÁ´Â·×´Ì¬¼ì²é»úÖÆ
393¡¢ÔÚUSG²úÆ·ÅäÖÃÖУ¬Èç¹û°ó¶¨WebÍø¹ÜºÍIPµØÖ·Ê±ÉèÖõĶ˿ںÅΪ443ÒÔÍâµÄÈð¿ÚºÅ£¬ÄÇôÔÚÏ´εǼWebÍø¹ÜÊäÈëIPµØÖ·Ê±£¬ÇëÔÚIPµØÖ·ºóÃæ¼ÓÉÏ\¶Ë¿ÚºÅ¡°£¬È硱
https://x.x.x.x£ºport¡°£¬·ñÔò½«²»ÄܵǼWebÍø¹Ü¡£------------------------------------------------------T