User VPN Flashcards

1
Q

5 principles of Aviatrix User VPN

A

1 - Connect users to public cloud resources
2 - Cloud native (not backhaul to on-prem DC first)
3 - Least latency access
4 - enterprise grade: identity provider intergration
5 - multi-cloud repeatability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What clients are supported with Aviatrix User VPN

A

OpenVPN

Aviatrix VPN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Aviatrix VPN client is preferred when?

A
  • Client has MacOs, Windows, Linux or BSD

- require SAML authentication directly from VPN client software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Aviatrix User VPN Automates …..

A

Launch cloud native loadbalancer
automate target groups to attache VPN gateways to LB
domain name of the vpn endpoint
connection ip created for .ovpn cert file to provide to clients
seemless relaunch of VPN gateways ofter deletion without reissue new .ovpn files (same IP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A profile can be __________ with multiple users

A

associated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

a user can be _________ with multiple profiles

A

associated

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

security based on use not _______

A

source IP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

supports _______ profiles

A

multiple

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

__________ firewall rules

A

Automates

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Geo VPN usage:

A

dynamically route VPN users to nearest Aviatrix VPN gateway based upon latency between user and gateways
users directed to AWS Route 53/Azure DNS that uses latency based routing policy OR choose between available regions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Default User VPN CIDR Block

A

192.168.43.0/24

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Client Certificate Sharing facets

A

Disabled by default
Multiple users share same ovpn file
only used when authenticating with IDP
controller sess individual users, maintains history

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

How to preserver Client IP

A

VPN NAT must be disabled

VPN CIDRs must be advertised to transit for return traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

PBR stands for?

A

Policy Based Routing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Reasons to use PBR Routing

A

Route VPN traffic via different gateway
anonymous web surfing
backhauling user traffic to cloud firewalls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

user VPN client connection options

A

1 - Enforce minimum VPN client version

2 - Duplicate connections (disable for single connection policy)

17
Q

To segment VPN users, tunnel access can be _______ OR _______

A
Split Tunnel (specify certain CIDRs)
Full Tunnel - All user IP sessions including Internet IP sessions go thru VPN tunnel
18
Q

Aviatrix UserVPN authentication supports SAML …

A

Secure assertion markup language
support IDPs like Azure AD, Okta, Duo, Office365
user accounts onboarded on the IDP portal
users can be onboarded on Aviatrix if SAML is NOT required

19
Q

FQDN Egress Filtering types (3)

A

HTTP - support wildcards
HTTPS - support wildcard after analyzing Server Name Identification in TLS
Other TCP/UDP, SFTP/SSH - does not support wildcards

20
Q

Egress FQDN filtering facets

A

HA secure for workloads or applications
centrally managed by controller
Filters internet bound egress traffic from workloads
filter tcp/udp traffic
filter destination host names allow/deny list
support wildcard and tags
supports instance in public/private subnets