Which encapsulation type must be configured on the lt-0/0/0 logical units for an interconnect
logical systems VPLS switch?
You want to enable transparent mode on your SRX series device.
In this scenario, which three actions should you perform? (Choose three.)
You have a multinode HA default mode deployment and the ICL is down.
In this scenario, what are two ways that the SRX Series devices verify the activeness of their peers? (Choose two.)
Comprehensive Detailed Step-by-Step Explanation with All Juniper Security Reference
Understanding the Scenario:
Multinode HA Default Mode Deployment:
In a chassis cluster, two SRX devices operate together to provide high availability.
ICL (Inter-Cluster Link) is Down:
The control and fabric links between the nodes are not operational.
Objective:
Determine how the SRX devices verify each other's activeness without the ICL.
Option A: Custom IP addresses may be configured for the activeness probe.
When the control link is down, SRX devices use an ICMP ping-based activeness probe to check the peer's status.
Custom IP addresses can be configured as probe targets to verify the peer's activeness.
'You can configure the SRX Series device to send activeness probes to a configured IP address to verify the peer's state when the control link is down.'
Source: Juniper Networks Documentation - Control Link Failure Detection
Option D: Each peer sends a probe with the virtual IP address as the source IP address and the upstream router as the destination IP address.
The SRX devices send ICMP probes to an upstream device using the redundancy group's virtual IP address as the source.
This helps determine if the peer node is still active by verifying network reachability.
'When the control link fails, each node sends ICMP pings to the configured probe addresses using the redundancy group's virtual IP address as the source.'
Source: Juniper Networks Documentation - Chassis Cluster Control Link Failure
Why Options B and C are Incorrect:
Option B: Fabric link heartbeats cannot be used because the ICL (which includes the fabric link) is down.
Option C: Probes are sent to upstream devices, not using the virtual IP address as the destination.
Conclusion:
The correct options are A and D because they accurately describe how SRX devices verify activeness without the ICL.
Click the Exhibit button.
Referring to the exhibit. SRX-1 and SRX-3 have to be connected using EBGP. The BGP configuration on SRX-1 and SRX-3 is verified and correct.
Which configuration on SRX-2 would establish an EBGP connection successfully between SRX-1 and SRX-3?
Comprehensive Detailed Step-by-Step Explanation with All Juniper Security Reference
Understanding the Scenario:
SRX-1 and SRX-3:
Need to establish an EBGP session through SRX-2.
Issue:
BGP session is not coming up despite correct configurations on SRX-1 and SRX-3.
Option D: The security policy to allow SRX-1 and SRX-3 to communicate on TCP port 179 should be configured.
BGP uses TCP port 179 for establishing sessions.
SRX-2 must have a security policy allowing traffic between SRX-1 and SRX-3 on TCP port 179.
'Security policies must permit BGP traffic (TCP port 179) to allow BGP sessions through the SRX device.'
Source: Juniper TechLibrary - Configuring Security Policies for Transit Traffic
Why Other Options Are Incorrect:
Option A: Host-inbound-traffic affects traffic destined to SRX-2, not transit traffic.
Option B and C: TCP ports 79 and 169 are unrelated to BGP.
Conclusion:
The correct option is D, configuring a security policy to allow TCP port 179.
Una
7 days agoTess
11 days agoTomas
1 months agoEstrella
1 months agoArlene
2 months agoDenise
2 months agoLashawn
2 months agoXochitl
3 months agoMonte
3 months agoMarkus
3 months agoBlair
3 months agoJade
3 months ago