F5 Management Access - TMOS 201 Flashcards

1
Q

What is the default ip for BIG-IP hardware?

A

192.168.1.245/24

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the default ip for VIPRION?

A

192.168.1.246/24

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the default credentials for HTTPS (configuration utlity)?

A

admin/admin

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the default SSH credentials

A

root/default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is port lockdown?

A

The port lockdown feature allows you to secure the BIG-IP system from unwanted connection attempts by controlling the level of access to each self IP address defined on the system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the port lockdown options?

A

1) Default
2) Allow none
3) Allow all
4) Custom
5) Custom (with default)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the default port lockdown setting?

A

Allow none

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the recommended port lockdown setting for failover on an HA self-ip?

A

Custom, UDP, port 1026

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the default management ip for Big-IP virtual edition?

A

None, as it is set as a DHCP client and will be assigned one by the DHCP server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where do you configure the management ip via the configuration utility?

A

System > Platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the commands to configure the management ip via TMSH?

A

1) create /sys management-ip [ip address/netmask]
2) create /sys management-route default gateway <gateway></gateway>

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or false: access to the management ip is either through management interface or data interface.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

By default, is access to the management interface from all ip addresses?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Where do you configure management ssh access in the configuration utility?

A

System > Platform

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or false: port lockdown is configured per self-ip address.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the iQuery port?

A

TCP 4353

17
Q

What are packet filters?

A

A network security feature that accepts or rejects traffic based on rules. Can be applied to management or data traffic.

18
Q

Are packet filters enabled by default?

A

No

19
Q

Where are packet filters configured in the configuration utility?

A

Network > Packet Filters

20
Q

What are the four packet filter options?

A

1) Accept - accept packet and stop processing other rules.
2) Discard - drop packets and stop processing other rules.
3) Reject - drop packets, stop processing rules, and send a reject packet to the sender.
4) Continue - accept the packet and continue process other rules. Logging can be enabled.

21
Q

What are options for the packet filter configuration?

A

1) Order
2) Action
3) Logging
4) Protocol
5) Source Host / Network
6) Destination Host / Network
7) Destination Port

22
Q

What is the BigIP listener order of precedence?

A

1) Packet filters (if filter established connection is enabled)
2) Connection table
3) Packet filter
4) Virtual server
5) SNAT / NAT