Regarding IPsec CoS-based VPNs, what is the number of IPsec SAs associated with a peer based upon?
A. The number of traffic selectors configured for the VPN.
B. The number of CoS queues configured for the VPN.
C. The number of classifiers configured for the VPN.
D. The number of forwarding classes configured for the VPN.
Your IPsec VPN configuration uses two CoS forwarding classes to separate voice and data traffic. How many IKE security associations are required between the IPsec peers in this scenario?
B. 3
C. 4
D. 2
What are two valid modes for the Juniper ATP Appliance? (Choose two.)
A. flow collector
B. event collector
C. all-in-one
D. core
Exhibit
You are implementing filter-based forwarding to send traffic from the 172.25.0.0/24 network through ISP-1 while sending all other traffic through your connection to ISP-2. Your ge- 0/0/1 interface connects to two networks, including the 172.25.0.0/24 network. You have implemented the configuration shown in the exhibit. The traffic from the 172.25.0.0/24 network is being forwarded as expected to 172.20.0.2, however traffic from the other network (172.25.1.0/24) is not being forwarded to the upstream 172.21.0.2 neighbor.
In this scenario, which action will solve this problem?
A. You must specify that the 172.25.1.1/24 IP address is the primary address on the ge- 0/0/1 interface.
B. You must apply the firewall filter to the lo0 interface when using filter-based forwarding.
C. You must add another term to the firewall filter to accept the traffic from the 172.25.1.0/24 network.
D. You must create the static default route to neighbor 172.21 0.2 under the ISP-1 routing instance hierarchy.
Exhibit
You configure a traceoptions file called radius on your returns the output shown in the exhibit What is the source of the problem?
A. An incorrect password is being used.
B. The authentication order is misconfigured.
C. The RADIUS server IP address is unreachable.
D. The RADIUS server suffered a hardware failure.
Exhibit.
Referring to the exhibit, a spoke member of an ADVPN is not functioning correctly.
Which two commands will solve this problem? (Choose two.)
A. [edit interfaces] user@srx# delete st0.0 multipoint
B. [edit security ike gateway advpn-gateway] user@srx# delete advpn partner
C. [edit security ike gateway advpn-gateway] user@srx# set version v1-only
D. [edit security ike gateway advpn-gateway] user@srx# set advpn suggester disable
Exhibit You are using trace options to verity NAT session information on your SRX Series device Referring to the exhibit, which two statements are correct? (Choose two.)
A. This packet is part of an existing session.
B. The SRX device is changing the source address on this packet from
C. This is the first packet in the session
D. The SRX device is changing the destination address on this packet 10.0.1 1 to 172 20.101.10.
Exhibit
Which two statements are correct about the output shown in the exhibit. (Choose two.)
A. The source address is translated.
B. The packet is an SSH packet
C. The packet matches a user-configured policy
D. The destination address is translated.
Which two statements are correct regarding tenant systems on SRX Series devices? (Choose two.)
A. A maximum of 32 tenant systems can be configured on a physical SRX device.
B. All tenant systems share a single routing protocol process.
C. Each tenant system runs its own instance of the routing protocol process
D. A maximum of 500 tenant systems can be configured on a physical SRX device.
You issue the command shown in the exhibit.
Which policy will be active for the identified traffic?
A. Policy p4
B. Policy p7
C. Policy p1
D. Policy p12