101-01 · Question #212
You have a SteelHead with paths over a public and a private network. You want to encrypt the traffic which goes via the public network. Which are the relevant SteelHead configuration requirements?…
The correct answer is B. The network must be set to 'public' by ticking the 'Public Network' box in the configuration. B: Because secure transport was built taking hybrid networking into account, you can configure a private and public IP address. The public IP address relies on reachability over a network marked Public. This configurations allows the controller to first be reached over the…
Question
You have a SteelHead with paths over a public and a private network. You want to encrypt the traffic which goes via the public network. Which are the relevant SteelHead configuration requirements? (Choose two.)
Options
- AThe peer SteelHead must be marked as a Cloud SteelHead in the local SteelHead peering table.
- BThe network must be set to 'public' by ticking the 'Public Network' box in the configuration.
- CA SteelCentral Controller for SteelHead must be used to push the secure transport configuration.
- DThe In-Path IP address of the SteelHead must be in public address space.
How the community answered
(38 responses)- A5% (2)
- B82% (31)
- C3% (1)
- D11% (4)
Explanation
B: Because secure transport was built taking hybrid networking into account, you can configure a private and public IP address. The public IP address relies on reachability over a network marked Public. This configurations allows the controller to first be reached over the private network and then the public network. C: The management plane is configured on the SCC using SSL and SSH secured communications, in which you create and distribute the path selection policy. When a network is marked as securable, it indicates that the SteelHead will join a group of other SteelHeads that can encrypt traffic. The SCC pushes the path selection policy to all the SteelHeads. Not D: The configurations allows the controller to first be reached over the private network and then the public network. The private and public IP addresses do not need to come from the same in-path interface. With the stp-client controller in-path enable command, the data center SteelHead (DC-SH) uses the private and public IP addresses from the same in-path interface, while the branch office SteelHead (BR-SH) uses the private and public IP addresses from different in-path interfaces.
Topics
Community Discussion
No community discussion yet for this question.