Deployment Options Flashcards

1
Q

What are the two deployment types? ( x2 traffic flow paths)

A
  1. In Path (in line)
  2. Out of Path - Quite complicated
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the 3 different deployment modes for the EdgeConnect appliance?

A
  1. Router Mode - as in: In Line Router Mode (ILRM)
  2. Bridge Mode - also inline but is ‘transparent’ within the same subnet
  3. Server Mode - Default for EdgeConnect VMs but will likely be changed to a different type of mode.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is one advantage of Bridge Mode on a physical appliance.

A

Fail-to-Wire feature that acts like a cross over cable when the device is powered off.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does the Server Mode deployment type work?

A

Only one network interface.

Traffic must be redirected to the SilverPiek device in both directions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some limitations of bridge mode?

A
  1. No Local Breakout
  2. Less path flexability
  3. No EdgeHA Mode
  4. No ZBF (Zone based Firewall) functionality
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the best protocol to support traditional HA deployments of EdgeConnect in Edge mode

A

VRRP - Virtual Router Redundancy Protocol

Two edge routers share a virtual IP and MAC address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the best way to deploy an HA pair of edge devices without the need for extra switches on the WAN side of the devices?

A

Edge High Avalability

devices share the wan connections between then where needed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does a router direct traffic to a silver piek that is not inline with the traffic?

A

Either…

Adversite the destination networks using the best metrics to local routers

or…

Policy Based Routing (PBR) on the in-line router.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Would you employ rate limiting on the device sending traffic or on the Silver Peak appliance?

A

On the Silver Peak Appliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the Firewall mode “WAN Hardening” do?

A

Only tunnel traffic will be allowed through the interface along with DHCP, DNS, and cloud portal managment traffic.

Return traffic from internet browsing would be blocked if internet breakout was attempted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What does the Stateful Firewall mode of the EdgeConnect device do?

A

Acts as a very basic statful firewall but does not do any filtering such as IPS or inspection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the Stateful+ Firewall mode of the EdgeConnect device do?

A

Acts as a statful firewall plus NAT functionality but does not do any filtering such as IPS or inspection.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How does ta SilverPeak Edge device support internal Server?

A

Inbound Port Forwarding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is a Zone Based Firewall (ZBF)?

A

Each inside and outside port as well as “business intent overlays” are assigned to a zone and then traffic behind zones can be controlled.
The Zone list is shared among all sites to allow setup or rules for the entire multi-site WAN network.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Does the EdgeConnect device need direct access to the internet.

A

No. The EdgeConnect device can talk over a private network link to the Orchestrator and the orchestrator can act as a proxy to reach the Silver Peak Cloud Portal to register.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Will the SilverPeak EdgeConnect device work behind a device that performs NAT?

A

Yes.