Juniper
JN0-632 · Question #37
A site-to-site VPN is configured between satellite offices and headquarters using a digital certificate from a neutral party. Once the VPN is up and stable, the certificate issued by the neutral…
The correct answer is A. Configure the SRX Series device with refresh-interval. C. Specify a URL to retrieve the CRL using HTTP or LDAP. See the full explanation below for the reasoning.
Question
A site-to-site VPN is configured between satellite offices and headquarters using a digital certificate from a neutral party. Once the VPN is up and stable, the certificate issued by the neutral party is revoked. The next-update time is not contained in the CRL. Which two actions should you take to ensure that the SRX Series device renegotiates the VPN faster? (Choose two.)
Options
- AConfigure the SRX Series device with refresh-interval.
- BWait for the default timer to expire; the device will then renegotiate the VPN tunnel.
- CSpecify a URL to retrieve the CRL using HTTP or LDAP.
- DConfigure the next-update time in the CRL.
How the community answered
(51 responses)- A80% (41)
- B12% (6)
- D8% (4)
Community Discussion
No community discussion yet for this question.