F5 Management Access - TMOS 201 Flashcards
What is the default ip for BIG-IP hardware?
192.168.1.245/24
What is the default ip for VIPRION?
192.168.1.246/24
What are the default credentials for HTTPS (configuration utlity)?
admin/admin
What are the default SSH credentials
root/default
What is port lockdown?
The port lockdown feature allows you to secure the BIG-IP system from unwanted connection attempts by controlling the level of access to each self IP address defined on the system.
What are the port lockdown options?
1) Default
2) Allow none
3) Allow all
4) Custom
5) Custom (with default)
What is the default port lockdown setting?
Allow none
What is the recommended port lockdown setting for failover on an HA self-ip?
Custom, UDP, port 1026
What is the default management ip for Big-IP virtual edition?
None, as it is set as a DHCP client and will be assigned one by the DHCP server.
Where do you configure the management ip via the configuration utility?
System > Platform
What are the commands to configure the management ip via TMSH?
1) create /sys management-ip [ip address/netmask]
2) create /sys management-route default gateway <gateway></gateway>
True or false: access to the management ip is either through management interface or data interface.
True
By default, is access to the management interface from all ip addresses?
Yes
Where do you configure management ssh access in the configuration utility?
System > Platform
True or false: port lockdown is configured per self-ip address.
True
What is the iQuery port?
TCP 4353
What are packet filters?
A network security feature that accepts or rejects traffic based on rules. Can be applied to management or data traffic.
Are packet filters enabled by default?
No
Where are packet filters configured in the configuration utility?
Network > Packet Filters
What are the four packet filter options?
1) Accept - accept packet and stop processing other rules.
2) Discard - drop packets and stop processing other rules.
3) Reject - drop packets, stop processing rules, and send a reject packet to the sender.
4) Continue - accept the packet and continue process other rules. Logging can be enabled.
What are options for the packet filter configuration?
1) Order
2) Action
3) Logging
4) Protocol
5) Source Host / Network
6) Destination Host / Network
7) Destination Port
What is the BigIP listener order of precedence?
1) Packet filters (if filter established connection is enabled)
2) Connection table
3) Packet filter
4) Virtual server
5) SNAT / NAT