HCNA °²È«Ìâ¿â H12-711 ÏÂÔØ±¾ÎÄ

353¡¢°ü¹ýÂË·À»ðǽÔÚÓ¦Óòã¶Ôÿһ¸öÊý¾Ý°ü½øÐмì²é£¬¸ù¾ÝÅäÖõݲȫ²ßÂÔת·¢»ò¶ªÆúÊý¾Ý°ü¡£--------------------------------------F

354¡¢´úÀí·À»ðǽ×÷ÓÃÓÚTCP/IPЭÒéÕ»µÄ´«Êä²ã£¬ÊµÖÊÊÇ´úÀí·À»ðǽ´úÀí´¦ÀíÄÚ²¿ÍøÂçºÍÍâ²¿ÍøÂçÓû§Ö®¼äµÄÒµÎñ¡£-------------------F

355¡¢add-group { number 1 name } no-pat ÖÐno-pat ²ÎÊýµÄº¬ÒåÊÇ:

A¡¢²»×öµØÖ·×ª»» B¡¢½øÐж˿ڸ´Óà C¡¢²»×ª»»Ô´¶Ë¿Ú D¡¢²»×ª»»Ä¿µÄ¶Ë¿Ú

356¡¢ÐÅÏ¢¼ÓÃܵÄËĸö¹Ø¼üÒªËØ£ºÃ÷ÎÄ¡¢ÃÜÎÄ¡¢¼ÓÃÜËã·¨ºÍÃÜÔ¿£¬ÎªÁËÈ·±£ÐÅÏ¢µÄ±£ÃÜÐÔ£¬Ðè¶Ô¼ÓÃÜËã·¨½øÐб£ÃÜ¡£------------------------------F 357¡¢IP SecÖÐÒÔÏÂÄĸöËã·¨²»ÊôÓÚ¼ÓÃÜËã·¨:

A¡¢DES B¡¢SHA1 C¡¢3DES D¡¢AES

358¡¢USG²úÆ·Îļþ¹²Ïí¼¼Êõ¾ÍÊǽ«Îļþ¹²ÏíЭÒéת»»³É»ùÓÚSSL³¬Îı¾´«ÊäЭÒé(Https)£¬Õë¶ÔÖÕ¶ËÓû§¸Ð¾õÎļþ·þÎñÆ÷¾ÍÊÇ»ùÓÚWebÓ¦Óá£----------------------------T

359¡¢USGϵÁзÀ»ðǽĬÈϵİ²È«ÇøÓò²»ÄÜɾ³ý£¬µ«¿ÉÒÔÐÞ¸ÄÆä°²È«¼¶±ð¡£---------------------------------F

360¡¢ÏÂÃæÃèÊöÊÇSSLÎÕÊÖЭÒé¸÷½×¶ÎÖеÄÄÚÈÝÓÐÄÄЩ?£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢¿Í»§¶Ë·¢ËÍclient_HelloÏûÏ¢£¬·þÎñÆ÷¶Ë»ØÓ¦Server HelloÏûÏ¢ B¡¢·þÎñÆ÷¶Ë·¢ËÍServer Hello±ãµÈ´ý¿Í»§¶Ë·¢Ë͵ÄÏûÏ¢

C¡¢¿Í»§¶ËÊÕµ½·þÎñÆ÷·¢Ë͵ÄһϵÁÐÏûÏ¢²¢Ïû»¯ºó£¬·¢ËÍClient Key ExchangeµÈÏûÏ¢¸ø·þÎñÆ÷

D¡¢¿Í»§¶ËºÍ·þÎñÆ÷¸÷×Ô·¢ËÍChangeCipherSpecºÍfinishedÏûÏ¢¸ø¶Ô·½ 361¡¢Policy Center×¼Èë¿ØÖÆ¿ÉÖ§³ÖÒÔÏÂÄÄЩ:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢Ó²¼þSACG(Ó²¼þ°²È«½ÓÈë¿ØÖÆÍø¹Ø) B¡¢802.1X C¡¢ARP¿ØÖÆ

D¡¢Èí¼þSACG(Ö÷»ú·À»ðǽ) 362¡¢USG²úÆ·ÅäÖÃʱ£¬VPNDBÖеÄÓû§ÐÅÏ¢¿ÉÒÔµ¥¸ö´´½¨£¬Ò²¿ÉÒÔͨ¹ýµ¼ÈëÎļþÅúÀï´´½¨¡£------------------------------------T

363¡¢SSL VPNÖ§ÌØÎļþ¹²ÏíÀàÐÍ·ÖΪSMBºÍNFSÁ½ÖÖ£¬SMB¶ÔÓ¦windowsÖ÷»ú£¬NFS¶ÔÓ¦LinuxÖ÷»ú¡£--------------------------------T

364¡¢»ùÓÚOutbound·½ÏòNATÅäÖã¬ÔÚÓÐno-patÅäÖòÎÊýµÄÇé¿öÏ£¬ÒÔÏÂÄÄЩ˵Ã÷ÊÇ´íÎóµÄ:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢Ö»½øÐÐÔ´IPµØÖ·×ª»» B¡¢Ö»½øÐÐÄ¿µÄIPµØÖ·×ª»» C¡¢½øÐÐÔ´IPµØÖ·ºÍÔ´¶Ë¿Úת»»

D¡¢½øÐÐÄ¿µÄIPµØÖ·ºÍÄ¿µÄ¶Ë¿Úת»»

365¡¢Poliry Centerϵͳ֧³ÖÒÔÏÂÄÄЩÓû§ÈÏÖ¤·½Ê½:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢IPµØÖ·ÈÏÖ¤ B¡¢MACµØÖ·ÈÏÖ¤

C¡¢ÆÕͨÕ˺Å/¿ÚÁîÈÏÖ¤ D¡¢LDAPÈÏÖ¤

366¡¢ÏÂÁйØÓÚ²»Í¬ÀàÐ͵ķÀ»ðǽµÄ˵·¨ÖÐÕýÈ·µÄÓÐ:£¨Ñ¡Ôñ3¸ö´ð°¸}

A¡¢°ü¹ýÂË·À»ðǽ¶ÔÓÚͨ¹ý·À»ðǽµÄÿ¸öÊý¾Ý°ü£¬¶¼Òª½øÐÐACLÆ¥Åä¼ì²é B¡¢×´Ì¬¼ì²â·À»ðǽֻ¶ÔûÓÐÃüÖлỰµÄÊ×°ü½øÐа²È«²ßÂÔ¼ì²é

C¡¢×´Ì¬¼ì²â·À»ðǽÐèÒªÅäÖñ¨Îĵġ°È¥¡±ºÍ¡°»Ø¡±Á½¸ö·½ÏòµÄ°²È«²ßÂÔ D¡¢´úÀí·À»ðǽ´úÀíÄÚ²¿ÍøÂçºÍÍâ²¿ÍøÂçÓû§Ö®¼äµÄÒµÎñ 367¡¢¹ÜÀíÔ±´î½¨ÁËÈçÏÂ×éÍø:

LAN_A----Ò»£¨G0/0)USG_A(G0/1)----Ò»(G0/0)USG_B(G0/1)-------LAN_B

USG_A»®·ÖÁË·À»ðǽ°²È«ÇøÓò£¬Á¬½ÓLAN_AµÄÇøÓòTrust,Á¬½ÓUSG_BµÄÇøÓòÊÇUntrust¸ù¾ÝÉÏÃæµÄÃèÊö£¬ÒÔÏÂ˵·¨ÕýÈ·µÄÊÇ:

A¡¢USG_B G0/0±ØÐë¼ÓÈëUntrustÇøÓò B¡¢USG_B G0/0±ØÐë¼ÓTrustÇøÓò C¡¢USG_B G0/1±ØÐë¼ÓTrustÇøÓò D¡¢USG_B G0/0¿ÉÒÔ¼ÓÈëÈÎÒâÇøÓò

368¡¢ÔÚIKEЭÉ̵ÚÒ»½×¶ÎÖУ¬ÒÔÏÂÄĸöIKE½»»»Ä£Ê½²»ÄÜÌṩÉí·Ý±£»¤¹¦ÄÜ:

A¡¢Ö÷ģʽ B¡¢Ò°Âùģʽ C¡¢¿ìËÙģʽ D¡¢±»¶¯Ä£Ê½

369¡¢USG·À»ðǽ¸ß¼¶ACLµÄÆ¥Å䣬¿ÉÒÔͨ¹ýÔ´IPµØÖ·¡¢Ä¿µÄIPµØÖ·¡¢Ô´MACµØÖ·¡¢Ä¿µÄMACµØÖ·¡¢Ð­ÒéµÈά¶ÈÀ´½øÐÐÁ÷ÀïÆ¥Åä¡£------------------F

370¡¢ÏÂÁйØÓÚNATµØÖ·×ª»»µÄ˵·¨ÖÐÄÄЩÊÇÕýÈ·µÄ:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢µØÖ·×ª»»¼¼Êõ¿ÉÒÔÓÐЧÒþ²Ø¾ÖÓòÍøÄÚµÄÖ÷»ú£¬ÊÇÒ»ÖÖÓÐЧµÄÍøÂ簲ȫ±£»¤¼¼Êõ B¡¢µØÖ·×ª»»¿ÉÒÔ°´ÕÕÓû§µÄÐèÒª£¬ÔÚ¾ÖÓòÍøÄÚÏòÍâÌṩFTP¡¢WWW¡¢TelnetµÈ·þÎñ C¡¢ÓÐЩӦÓòãЭÒéÔÚÊý¾ÝÖÐЯ´øIPµØÖ·ÐÅÏ¢£¬¶ÔËüÃÇ×÷NATʱ»¹ÒªÐÞ¸ÄÉϲãÊý¾ÝÖеÄIPµØÖ·ÐÅÏ¢

D¡¢¶ÔÓÚijЩ·ÇTCP¡¢UDPµÄЭÒ飨ÈçICMP¡¢PPTP)£¬ÎÞ·¨×öNATת»»

371¡¢ÔÚUSGϵÁзÀ»ðÇ½ÇøÓò¼äʹÓÃdetectÃüÁÈôÓ¦ÓÃЭÒéΪ·Ç±ê×¼¶Ë¿Ú£¬ÒÔÏÂÄĸö¼¼Êõ¿É½â¾öÓɷDZê×¼¶Ë¿ÚËù´øÀ´µÄÎÊÌâ:

A¡¢¶Ë¿Úʶ±ð

B¡¢MACÓëIPµØÖ·°ó¶¨ C¡¢°ü¹ýÂË D¡¢³¤Á¬½Ó

372¡¢ÒÔÏÂÄÄÀà¼ÓÃÜËã·¨£¬¼ÓÃܺͽâÃܵÄÃÜÔ¿ÊÇÏàͬµÄ:

A¡¢DES

B¡¢RSA£¨1024£© C¡¢MD5 D¡¢SHA-1

373¡¢USG²úÆ·ÍøÂçÀ©Õ¹¹¦ÄÜÖУ¬ÐèҪʵÏÖÓû§¼´¿ÉÒÔ·ÃÎÊÔ¶¶ËÆóÒµÄÚÍøºÍ±¾µØ¾ÖÓòÍø£¬ÓÖÄÜ·ÃÎÊInternetÐèҪʹÓõĿͻ§¶Ë·ÓÉ·½Ê½Îª:

A¡¢È«Â·ÓÉģʽ(Full Tunnel) B¡¢·ÖÀëģʽ£¨Split Tunnel £© C¡¢Â·ÓÉģʽ(route Tunnel)

D¡¢ÊÖ¶¯Ä£Ê½(Manual Tunnel)

374¡¢Policy Centerϵͳ¿ÉÒÔʵÏÖ×éÖ¯¹ÜÀíºÍÇøÓò¹ÜÀíÁ½¸öά¶ÈµÄ¹ÜÀí¹¦ÄÜ¡£-----------------------------------------T

375¡¢ÏÂÁйØÓÚASPFºÍServer mapµÄ˵·¨ÕýÈ·µÄÊÇ:¡²Ñ¡Ôñ2¸ö´ð°¸£©

A¡¢ASPF¼ì²éÓ¦ÓòãЭÒéÐÅÏ¢²¢ÇÒ¼à¿ØÁ¬½ÓµÄÓ¦ÓòãЭÒé״̬ B¡¢ASPFͨ¹ý¶¯Ì¬µÄÉú³ÉACLÀ´¾ö¶¨Êý¾Ý°üÊÇ·ñͨ¹ý·À»ðǽ C¡¢ÅäÖÃNAT ServerÉú³ÉµÄÊǾ²Ì¬Server-map D¡¢Server-map±íÓÃÎåÔª×éÀ´±íʾһÌõ»á»°

396¡¢ USG²úÆ·¿ÉÒÔͨ¹ýÈçÏÂÄÄЩ·½Ê½¶ÔÓû§½øÐзÃÎÊȨÏÞ¿ØÖÆ:

A¡¢IP B¡¢MAC C¡¢PORT D¡¢URL

377¡¢USG²úÆ·ÒµÎñ¹¦ÄܰüÀ¨:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢Web´úÀí B¡¢ÍøÂçÀ©Õ¹ C¡¢¶Ë¿Ú¹²Ïí D¡¢Îļþ¹²Ïí

378¡¢Policy CenterϵͳµÄ¹²ÏíĿ¼¼ì²é°²È«²ßÂÔ°üÀ¨ÒÔÏÂÄÄЩ·½ÃæÄÚÈÝ:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢¹²ÏíÎļþ´óС¼ì²é£¬¶ÔÓÚ´óÎļþ²»ÔÊÐí¹²Ïí B¡¢¹²ÏíÕ˺ÅÃû³Æ(Óû§»òÕßÓû§×é)¼ì²é C¡¢Î¥¹æ¹²ÏíȨÏÞ¼ì²é

D¡¢Ìṩ×Ô¶¯ÐÞ¸´¹¦ÄÜ£¬É¾³ýÎ¥¹æ¹²Ïí

379¡¢Èç¹û·À»ðǽµÄÁ½¸ö½Ó¿ÚÁ¬½Óͬһ¸öÇøÓò£¬Á½¸ö½Ó¿ÚÊý¾Ý°üÁ÷¶¯Ò²±ØÐë¾­¹ýÓò¼ä°ü¹ýÂÇ´¦Àí¡£-----------------------------------F

380¡¢VLANµÄTagÐÅÏ¢°üº¬ÔÚÄĸö±¨ÎĶÎÖÐ:

A¡¢ÒÔÌ«ÍøÖ¡Í·ÖÐ B¡¢IP±¨ÎÄÍ·ÖÐ C¡¢TCP±¨ÎÄÍ·ÖÐ D¡¢UDP±¨ÎÄÍ·ÖÐ

381¡¢ÒÔÏÂÄÄЩ¼¼Êõ¿ÉÒÔʵÏ־ܾø·Ç·¨Ö÷»ú»ò·Ç·¨Êý¾Ý±¨ÎÄͨ¹ý:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢MACÓëlPµØÖ·°ó¶¨ B¡¢ACL C¡¢ºÚÃûµ¥ D¡¢¾²Ì¬Â·ÓÉ 382¡¢IPSec°²È«Ð­ÒéAHºÍESPµÄÇø±ðÔÚÓÚAHÄÜʵÏÖÊý¾Ý¼ÓÃÜ£¬ESPÖ§³ÖµÄÊý¾ÝÑéÖ¤·¶Î§¸ü¹ã¡£--------------------------------------F

383¡¢ÔÚµ±Ç°ÍøÂçÖÐÒѾ­²¿ÊðÁËÆäËûµÄÉí·ÝÈÏ֤ϵͳ£¬É豸ͨ¹ýÆôÓõ¥µãµÇ¼¹¦ÄÜ£¬¼õÉÙÓû§Öظ´ÊäÈëÃÜÂë¡£¹ØÓÚµ¥µãµÇ¼˵·¨ÕýÈ·µÄÊÇ:£¨Ñ¡Ôñ2¸ö´ð°¸£©

A¡¢É豸¿ÉÒÔʶ±ð³ö¾­¹ýÕâЩÉí·ÝÈÏ֤ϵͳÈÏ֤ͨ¹ýµÄÓû§£¬Óû§ÉÏÍøÊ±£¬É豸½«²»ÍÆËÍÈÏÖ¤Ò³Ãæ£¬±ÜÃâÔÙ´ÎÒªÇóÊäÈëÓû§Ãû/ÃÜÂë

B¡¢É豸½öÖ§³ÖADÓòµ¥µãµÇ¼

C¡¢ËäÈ»²»ÐèÒªÊäÈëÓû§ÃÜÂ룬µ«ÊÇÈÏÖ¤·þÎñÆ÷ÐèÒª½«Óû§ÃÜÂëºÍÉ豸½øÐн»»¥£¬ÓÃÀ´±£Ö¤ÈÏ֤ͨ¹ý

D¡¢É豸֧³ÖLDAP£¬ADÓòµ¥µãµÇ¼ 384¡¢ÒÔÏÂÄĸöIKE½»»»Ä£Ê½¿ÉÒÔ²ÉÓÃIPµØÖ··½Ê½»òName·½Ê½±êʶ¶ÔµÈÌ壨ѡÔñ:2¸ö´ð°¸£©

A¡¢Ö÷ģʽ B¡¢Ò°Âùģʽ C¡¢¿ìËÙģʽ D¡¢±»¶¯Ä£Ê½

385¡¢IPµØÖ·É¨Ãèõ»÷µÄ¹¥»÷ÕßÔËÓÃICMP±¨ÎÄ̽²âÄ¿±êµØÖ·£¬»ñȡĿ±êÍøÂçµÄÍØÆË½á¹¹ºÍ´æ»îµÄϵͳ£¬ÊµÊ©ÏÂÒ»²½¹¥»÷×ö×¼±¸¡£--------------------------------T

386¡¢ÔÚUSGϵÁзÀ»ðǽϵͳÊÓͼÏ£¬Ö´ÐÐÍêÃüÁîreset saved-configurationºóÉ豸ÅäÖþͻá»Ö¸´µ½È±Ê¡ÅäÖã¬ÎÞÐè½øÐÐÆäËû²Ù×÷¼´¿ÉÉúЧ¡£---------------------------------------------F 387¡¢Policy CenterϵͳÖ÷ÒªÓÉÒÔÏÂÄÄЩ×é¼þ×é³É:(Ñ¡Ôñ3¸ö´ð°¸)

A¡¢·À²¡¶¾·þÎñÆ÷ B¡¢SC¿ØÖÆ·þÎñÆ÷ C¡¢×¼Èë¿ØÖÆÉ豸 D¡¢SM¹ÜÀí·þÎñÆ÷

388¡¢ÔÚ·À»ðǽ¼ä°²È«²ßÂÔÖУ¬inboundÊÇÖ¸Êý¾Ý°ü´ÓµÍÓÅÏȼ¶ÇøÓò·ÃÎʸßÓÅÏȼ¶ÇøÓò¡£ÔÚ·À»ðǽÓòÄÚ°²È«²ßÂÔÖУ¬Ã»ÓÐinboundºÍoutbound·½Ïò£¬Ö»ÐèÒªÖ±½Ó¶¨ÒåSourceºÍDestination¼´¿É¡£--------------------------T

389¡¢¶ÔÓÚ·À»ðǽĬÈϰ²È«ÇøÓòTrustºÍUntrustµÄ˵·¨ÕýÈ·µÄÓÐ:£¨Ñ¡Ôñ2¸ö´ð°¸£©

A¡¢TrustÇøÓò·ÃÎÊUntrustÇøÓò·½ÏòΪoutbound·½Ïò B¡¢TrustÇøÓò·ÃÎÊUntrustÇøÓò·½ÏòΪinbound·½Ïò C¡¢TrustµÄ°²È«¼¶±ðÊÇ85 D¡¢UntrustµÄ°²È«¼¶±ðÊÇ50

390¡¢IPSecµÄ±ØÐèÅäÖò½Öè°üÀ¨: £¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢ÅäÖÃIKEµÄ¼ÓÃÜËãÈαãÓÃDES B¡¢¶¨Òå±£»¤Êý¾ÝÁ÷ºÍÓò¼ä¹æÔò C¡¢½«IPSec°²È«²ßÂÔÓ¦Óõ½½Ó¿Ú D¡¢ÅäÖÃIKE Peer

391¡¢USGϵÁзÀ»ðǽ5Ôª×é°üÀ¨ÒÔÏÂÄÄЩѡÏî:£¨Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢Ô´IPµØÖ· B¡¢Ä¿µÄIPµØÖ· C¡¢Ð­ÒéºÅ

D¡¢Ô´MACµØÖ·

392¡¢·À»ðǽ½øÐÐAVºÍIPSµÄÅäÖÃǰÐèÒªÍê³ÉÏÂÁвÙ×÷:¡²Ñ¡Ôñ3¸ö´ð°¸£©

A¡¢ÐèÒªÉêÇë²¢¼¤»îUTMÌØÐÔµÄlicense²¢Éý¼¶ÌØÕ÷¿â B¡¢Ö¸¶¨Ê¹ÓõIJ¡¶¾¿â¡¢IPSÇ©Ãû¿â¡¢URLÈȵã¿âºÍ֪ʶ¿â C¡¢È·ÈÏ·À»ðǽģʽΪUTMģʽ£¬ÆôÓÃUTM D¡¢¹Ø±Õ·À»ðǽÁ´Â·×´Ì¬¼ì²é»úÖÆ

393¡¢ÔÚUSG²úÆ·ÅäÖÃÖУ¬Èç¹û°ó¶¨WebÍø¹ÜºÍIPµØÖ·Ê±ÉèÖõĶ˿ںÅΪ443ÒÔÍâµÄÈð¿ÚºÅ£¬ÄÇôÔÚÏ´εǼWebÍø¹ÜÊäÈëIPµØÖ·Ê±£¬ÇëÔÚIPµØÖ·ºóÃæ¼ÓÉÏ\¶Ë¿ÚºÅ¡°£¬È硱

https://x.x.x.x£ºport¡°£¬·ñÔò½«²»ÄܵǼWebÍø¹Ü¡£------------------------------------------------------T