Question 96
BGP MPLS VPN 组网的某台公网设备上,采用 displa mpls ldp lsp 命令检查其标签转发表时,结果如下,说明。
[PE1] dis mpls ldp lsp
LDP LSP Information
-------------------------------------------------------------------------
SN DestAddress/Mask In/OutLabel Next-Hop In/Out-Interface
---------------------------------------------------------------------------------
1 1.1.1.1/32 3/NULL 127.0.0.1 Eth0/0/InLoop0
2 1.1.1.2/32 NULL/1024 100.0.0.2 ---------Eth0/0
3 1.1.1.3/32 NULL/3 100.0.0.2 ---------Eth0/0
[PE1] dis mpls ldp lsp
LDP LSP Information
-------------------------------------------------------------------------
SN DestAddress/Mask In/OutLabel Next-Hop In/Out-Interface
---------------------------------------------------------------------------------
1 1.1.1.1/32 3/NULL 127.0.0.1 Eth0/0/InLoop0
2 1.1.1.2/32 NULL/1024 100.0.0.2 ---------Eth0/0
3 1.1.1.3/32 NULL/3 100.0.0.2 ---------Eth0/0
Question 97
关于非对称加密算法说法正确的是。
Question 98
在 BGP MPLS VPN 的组网中,某一私网用户报文有两层 MPLS 标签,关于这两层 MPLS 标签的说法正确的是。
Question 99
在安全网关设备上通过 displa ipsec sa 命令显示如下信息,通过该信息可知。
Interface: Serial0/2/1
Path MTU: 1500
-----------------------------
IPsec polic name: "1"
Sequence number: 1
Mode: isakmp
-----------------------------
Connection id: 5
Encapsulation mode: transport
Perfect forward secrec: None
Tunnel :
Local address: 10.2.1.1
Remote address: 10.2.1.2
Flow:
Sour addr: 10.1.1.0/255.255.255.0 port: 0 protocol: IP
Dest addr: 10.3.1.0/255.255.255.0 port: 0 protocol: IP
[inbound ESP SAs]
Spi: 909448761 ( 0x36351639 )
Proposal: ESP-ENCRPT-DES ESP-AUTH-MD5
Sa remaining ke duration ( btes/sec ) : 1887435204/83
Max received sequence-number: 19
Udp encapsulation used for nat traversal: N
[outbound ESP SAs]
Spi: 1583842120 ( 0x5e678348 )
Proposal: ESP-ENCRPT-DES ESP-AUTH-MD5
Sa remaining ke duration ( btes/sec ) : 1887435204/83
Max sent sequence-number: 20
Udp encapsulation used for nat traversal: N
Interface: Serial0/2/1
Path MTU: 1500
-----------------------------
IPsec polic name: "1"
Sequence number: 1
Mode: isakmp
-----------------------------
Connection id: 5
Encapsulation mode: transport
Perfect forward secrec: None
Tunnel :
Local address: 10.2.1.1
Remote address: 10.2.1.2
Flow:
Sour addr: 10.1.1.0/255.255.255.0 port: 0 protocol: IP
Dest addr: 10.3.1.0/255.255.255.0 port: 0 protocol: IP
[inbound ESP SAs]
Spi: 909448761 ( 0x36351639 )
Proposal: ESP-ENCRPT-DES ESP-AUTH-MD5
Sa remaining ke duration ( btes/sec ) : 1887435204/83
Max received sequence-number: 19
Udp encapsulation used for nat traversal: N
[outbound ESP SAs]
Spi: 1583842120 ( 0x5e678348 )
Proposal: ESP-ENCRPT-DES ESP-AUTH-MD5
Sa remaining ke duration ( btes/sec ) : 1887435204/83
Max sent sequence-number: 20
Udp encapsulation used for nat traversal: N
Question 100
以下哪些 VPN 技术适用于企业员工 , 通过 Internet 远程接入企业私网的情况 ? ( 选择一项或多项 )
