Mx Flashcards
Auto VPN ports used by peers
Source ports UDP 32768-61000 for IPSec tunnel, VPN registry destination port UDP 9350
Exhibit showing appliance status of MX in VPN concentrator mode that’s having issues - what to do to resolve?
Probably unplug all LAN ports
Select two features supported in MX passthrough mode
“IDS/IPS, Site to Site VPN (assume Site to Site Auto VPN as referred to in doc) supported.
Note: HA is not supported (only supported in NAT/routed and one-arm VPN concentrator modes) “
Using a vMX for Azure offers what benefit over an IPSec VPN to Azure? SD-WAN, next gen f/w, intrusion prevention?
vMX can do HA and SD-WAN (SD-WAN was a choice in test)
Firmware upgrade order for MXs in HA pair
Primary downloads firmware and upgrades first (while secondary is active), then secondary
Exhibit showing MX routing table - what is next-hop for traffic from given source to given destination where latter is reachable via an Auto VPN tunnel?
Assume it should be particular Auto VPN peer destination, as shown on output (not default route next-hop of MX)
Where to check high WAN utilisation?
Current utilisation levels would be: Security Appliance > Appliance Status > Uplink tab
If a setting is changed on MX that was configured via template, what would be the behaviour?
“local overrides-Once a network has been bound to a template, some options can still be configured normally. Any local configuration changes made directly on the network will override the template configuration.
Note:
Updating the same options on the template will not clear a network’s local overrides. To clear local overrides, the network needs to be unbound and rebound to the template. “
Exhibit showing 3 networks (A,B,C) with VPNs between A&B and A&C. What is the MX Insight licence requirement when if troubleshooting data required on web app health on B
Need Insight licence on both networks A & B MXs or just on net B?
Answer needs to be confirmed
Exhibit showing SDWAN performance class configuration- what is preferred uplink for webex conference traffic
Configured preferred link(WAN2?) as long as performance class thresholds are satisified
No of tunnels on an Auto VPN hub, when there are 2 dual link hubs, 50 single link spokes
((2-1)x2^2) + 50x1x2 = 104
Drag & drop to select differences between NAT mode(routed) and passthrough mode MX setup
“NAT mode(default): NAT/DHCP support, acts as gateway for LAN
Passthrough/VPN Concentrator: no NAT/routing, no vlan config, not recommended for network perimeter”
Exhibit showing SD-WAN & traffic shaping - How to enable 4:1 ratio for traffic across WAN1/WAN2 uplinks
Set WAN1/2 bandwidths to give 4:1 ratio on Security &SD-WAN>SD-WAN & traffic shaping>Uplink configuration, and enable Load balancing on Uplink Selection section
exhibit - Security Centre log showing blocked traffic- which IDS/IPS mode used?
Blocking connections so ‘Prevention’ mode used
Which vlan ID is used by MX to source pings via Tools tab?
Highest vlan ID