IP Sec Flashcards

1
Q

What is the function of a IPsec transform set?

A

Defines Phase 2 tunnel encryption and hashing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the ASA PSK VPN Configuration Steps? (6)

A
Enable IKE on “outside” interface
Configure ISAKMP phase 1 policy
Configure IPSec L2L tunnel group
Configure traffic to allow through VPN
Configure IPSec transform set
Configure crypto map and assigned to “outside” interface.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How do you Configure traffic to allow through VPN?

A

Create network objects for source and destination networks

Create access list referencing network object

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

When configuring isakmp phase 1 policy you need to Defines Phase 1 _____ properties and ________ methods

A

When configuring isakmp phase 1 policy you need to Defines Phase 1 tunnel properties and authentication methods

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

When configuring IPSec L2L tunnel group you are required to defines VPN _____ and assign a?

A

When configuring IPSec L2L tunnel group you are required to defines VPN target IP and assign a Pre-shared key

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

When configuring crypto map and assigned to “outside” interface, its function is?

A

Pulls together allowed traffic, transform set and target address
May have variations in case multiple VPN with different parameters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What command is used to enable ASA Enable IKE?

A

crypto ikev1 enable outside

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What commands are used to configure a ASA Phase 1 Policy?

A
crypto ikev1 policy 1
encryption aes 256
hash sha
group 5
lifetime 86400
authentication pre-share
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What command is used to create a tunnel group?

A

tunnel-group 192.168.244.5 type ipsec-l2l
tunnel-group 192.168.244.5 ipsec-attributes
ikev1 pre-shared-key Secret55

How well did you know this?
1
Not at all
2
3
4
5
Perfectly