Mx Flashcards

1
Q

Auto VPN ports used by peers

A

Source ports UDP 32768-61000 for IPSec tunnel, VPN registry destination port UDP 9350

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Exhibit showing appliance status of MX in VPN concentrator mode that’s having issues - what to do to resolve?

A

Probably unplug all LAN ports

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Select two features supported in MX passthrough mode

A

“IDS/IPS, Site to Site VPN (assume Site to Site Auto VPN as referred to in doc) supported.
Note: HA is not supported (only supported in NAT/routed and one-arm VPN concentrator modes) “

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Using a vMX for Azure offers what benefit over an IPSec VPN to Azure? SD-WAN, next gen f/w, intrusion prevention?

A

vMX can do HA and SD-WAN (SD-WAN was a choice in test)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Firmware upgrade order for MXs in HA pair

A

Primary downloads firmware and upgrades first (while secondary is active), then secondary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Exhibit showing MX routing table - what is next-hop for traffic from given source to given destination where latter is reachable via an Auto VPN tunnel?

A

Assume it should be particular Auto VPN peer destination, as shown on output (not default route next-hop of MX)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Where to check high WAN utilisation?

A

Current utilisation levels would be: Security Appliance > Appliance Status > Uplink tab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

If a setting is changed on MX that was configured via template, what would be the behaviour?

A

“local overrides-Once a network has been bound to a template, some options can still be configured normally. Any local configuration changes made directly on the network will override the template configuration.
Note:
Updating the same options on the template will not clear a network’s local overrides. To clear local overrides, the network needs to be unbound and rebound to the template. “

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Exhibit showing 3 networks (A,B,C) with VPNs between A&B and A&C. What is the MX Insight licence requirement when if troubleshooting data required on web app health on B

A

Need Insight licence on both networks A & B MXs or just on net B?

Answer needs to be confirmed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Exhibit showing SDWAN performance class configuration- what is preferred uplink for webex conference traffic

A

Configured preferred link(WAN2?) as long as performance class thresholds are satisified

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

No of tunnels on an Auto VPN hub, when there are 2 dual link hubs, 50 single link spokes

A

((2-1)x2^2) + 50x1x2 = 104

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Drag & drop to select differences between NAT mode(routed) and passthrough mode MX setup

A

“NAT mode(default): NAT/DHCP support, acts as gateway for LAN
Passthrough/VPN Concentrator: no NAT/routing, no vlan config, not recommended for network perimeter”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Exhibit showing SD-WAN & traffic shaping - How to enable 4:1 ratio for traffic across WAN1/WAN2 uplinks

A

Set WAN1/2 bandwidths to give 4:1 ratio on Security &SD-WAN>SD-WAN & traffic shaping>Uplink configuration, and enable Load balancing on Uplink Selection section

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

exhibit - Security Centre log showing blocked traffic- which IDS/IPS mode used?

A

Blocking connections so ‘Prevention’ mode used

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which vlan ID is used by MX to source pings via Tools tab?

A

Highest vlan ID

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SD-WAN Performance class threshold checking - how and what packets are used for this?

A

“100 byte UDP packets sent over primary link(WAN1?)

(Assume only over one link as active/active VPN and/or load balancing are disabled)”