Hi All,

1. Swith VTY line numbers = If question asks to implement aaa authentication
on telnet lines on switch & router then which line numbers we should
consider from exam point of view?
Is it

   -  VTY 0 4
   - VTY 0 15
   - VTY 0 807

2. Large ICMP IP Signature tuning =

There are two separate questions on large ICMP signature

   - Configure a signature to fire if the size of an ICMP Packet is 5000
   bytes.
   - Fire an alarm if the size of an ICMP packet is greater than 1000 bytes.

We should configure "ICMP total length = 5000"  for first question.

And "IP payload length = 1000-65535" for second question.

Is this solution correct?

3. What ports need to be opened for GET-VPN in ASA if KS is behind NAT
device?
Are they: udp 500, 4500 and 848?


Regards,
DMG
_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to