QUESTION NO: 174

QUESTION NO: 174
You are the administrator of TestKing’s network, which consists of a single Windows 2000 domain. The
network has a persistent connection to the Internet. The relevant partition of its configuration is shown in
the exhibit. (Click the Exhibit button).

Your company employs mobile salespeople who use portable computers running Windows 2000
Professional. To enable these users to access internal resources you place a virtual private network (VPN)
server named VPN1 outside your firewall. This server is a stand-alone Windows 2000 Server computer
running Routing and Remote Access. The firewall is configured to allow inbound access from VPN1 only.

You configure L2TP ports on VPN1. Now you must configure additional output and input filters for the
external network adapter on VPN1. You must ensure that VPN1 allows only VPN traffic on the Internet
interface, and prevents non-VPN users from accessing internal resources.
Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)
A. Create an input filter on VPN1 that allows L2TP ports as destination ports.
As the destination IP address, use the IP address of the external interface of VPN1.
B. Create an input filter on VPN1 that allows L2TP ports as source ports.
As the source IP address, use the IP address of the external interface of VPN1.
C. Create an input filter on VPN1 that allows L2TP ports as destination ports.
As the destination IP address, use the IP address of the internal interface of VPN1.
D. Create an output filter on VPN1 that allows L2TP ports as source ports.
As the source IP address, use the IP address of the external interface of VPN1.
E. Create an output filter on VPN1 that allows L2TP ports as destination ports.
As the destination IP address, use the IP address of the external interface of VPN1.
F. Create an output filter on VPN1 that allows L2TP ports as source ports.
As the source IP address, use the IP address of the internal interface of VPN1.
Answer: A, F
Explanation:
A: The only inbound traffic allowed is traffic to the external interface on the VPN1 server.
F: The only outbound traffic allowed is traffic originating from the internal interface of VPN1.
Incorrect Answers:
B: Input filters must use the L2TP ports as destination ports, not source ports.
C: The only destination address allowed is the address of the external, not internal, VPN interface.
D: The source of an output filter must the IP address of the internal interface of VPN1.
E: In an output filter the L2TP ports must be used as a source ports.
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值