Implementing IPSec Site-to-Site VPNs Flashcards

1
Q

Name three things that can be part of both an IKE Phase 1 and IKE Phase 2 policy?

A

MD5, AES, Diffie-Hellman (DH)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How is it possible that a packet with a private Layer 3 destination address is forwarded over the Internet?

A

It is encapsulated into another packet, and the Internet only sees the outside valid IP destination address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the method for specifying the IKEv1 Phase 2 encryption method?

A

crpyto ipsec transform-set

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which method potentially could be negotiated during IKEv1 Phase 2?

A

Hashing, DH group, Encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the DH groups is the most prudent to use when security is of the utmost importance?

A

5

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Name three things that are part of an IKEv1 Phase 2 process?

A

Specifying a hash (HMAC), Running DH (PFS), Negotiating the transform set to use

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which encryption method is used to protect the negotiation of the IPSec (IKE v1 Phase2) tunnel?

A

The one that is negotiated in the ISAKMP policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the most secure method for authentication of IKE Phase 1?

A

RSA signatures, using digital certificates to exchange public keys

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What component is not placed directly in a crypto map?

A

Authentication policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What would cause a VPN tunnel using IPSec to never initialize or work correctly?

A

Incompatible IKEv1 Phase 2 transform set, Incorrect pre-shared key or missing digital cert, Lack of interesting traffic, Incorrect routing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What IKE versions are supported by the Cisco ASA?

A

IKEv1, IKEv2, IKEv3, IKEv4

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the purpose of NAT exemption?

A

To bypass NAT for traffic in the VPN tunnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What commands are useful when troubleshooting VPN problems in the Cisco ASA?

A

show isakmp sa detail, debug crypto ikev1 | ikev2, show crypto ipsec sa detail, show vpn-sessiondb

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

The Cisco ASA cannot be configured with more than one IKEv1 or IKEv2 policy?

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly