H12-731-ENU試験無料問題集「Huawei HCIE-Security (Huawei Certified Internetwork Expert-Security) 認定」
Huawei USG firewall, in the dual-system hot-standby network (as shown in the figure), the PC cannot log in to the real IP address of the external network port of the standby firewall FW2 through SSH. Check the corresponding sessions on the active and standby firewalls as follows, and analyze the following statements about this fault. is it right ?
HRP_A <E1000-1> display firewall session table verbose source inside 192.168.22.151
tcp VPN: public ->
public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: G0/0/1 Nexthop: 192.168.22.122 MAC: 00-22-a1-06-b3-cb
<-- packets: 1
bytes: 48 -> packets: 0 bytes: 0
192.168.22.122:22 <-- 192.168.22.151:4354
HRP_S <-E1000-2>display firewall session table verbose source inside 192.168.22.151
tcp VPN: public -> public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: I0 Nexthop: 127.0.0.1 MAC: 00-00-00-00-00-00
<-- packets: 1
bytes: 48 -> packets: 1 bytes: 44
192.168.22.122:22 <-- 192.168.22.151:4354

HRP_A <E1000-1> display firewall session table verbose source inside 192.168.22.151
tcp VPN: public ->
public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: G0/0/1 Nexthop: 192.168.22.122 MAC: 00-22-a1-06-b3-cb
<-- packets: 1
bytes: 48 -> packets: 0 bytes: 0
192.168.22.122:22 <-- 192.168.22.151:4354
HRP_S <-E1000-2>display firewall session table verbose source inside 192.168.22.151
tcp VPN: public -> public
Zone: trust -> local TTL: 00:00:05 Left: timeout
Interface: I0 Nexthop: 127.0.0.1 MAC: 00-00-00-00-00-00
<-- packets: 1
bytes: 48 -> packets: 1 bytes: 44
192.168.22.122:22 <-- 192.168.22.151:4354

正解:A,C
解答を投票する
When the network traffic is heavy, if you do not want the downstream network to be congested or directly discard a large number of packets due to the excessive data traffic sent by the upstream, you can limit and cache the traffic on the outbound interface of the upstream device, so that such packets can be compared with each other. Send out at an even speed.
This technique can be:
This technique can be:
正解:A
解答を投票する
The USG firewall is directly connected to other devices at Layer 3. During commissioning, it was found that the IP address of the peer directly connected to the firewall cannot be pinged, and it has been confirmed that there is no problem with the peer device. What are the possible reasons?
正解:B,C
解答を投票する