You cannot assign an interface to a functional zone.
You can specifiy a functional zone in a security policy.
Security zones must have a scheduler applied.
You can use a security zone for traffic destined for the device itself.
第1题:
A. There are five phases of IKE negotiation.
B. There are two phases of IKE negotiation.
C. IPsec VPN tunnels are not supported on SRX Series devices.
D. IPsec VPNs require a tunnel PIC in SRX Series devices.
第2题:
Which statement is true regarding Backup tasks in Cisco UCS?()
第3题:
A. Traffic is permitted from the trust zone to the untrust zone.
B. Intrazone traffic in the trust zone is permitted.
C. All traffic through the device is denied.
D. The policy is matched only when no other matching policies are found.
第4题:
In the Junos OS, which statement is true?()
第5题:
Which statement is true about interface-based source NAT?()
第6题:
A. It also supports PAT.
B. It requires you to configure address entries in the junos-nat zone.
C. It requires you to configure address entries in the junos-global zone.
D. The IP addresses being translated must be in the same subnet as the incoming interface.
第7题:
Which statement is true regarding the forwarding plane?()
第8题:
A. vlan.0 belongs to the untrust zone.
B. You must configure Web authentication to allow inbound traffic in the untrust zone.
C. The zone name "untrust" has no special meaning.
D. The untrust zone is not configurable.
第9题:
Which statement is true regarding the INTERSECT operator?()
第10题:
Which statement is true regarding syslog on Junos devices?()