Exam4Training

What should you do?

Your network contains an Active Directory domain named contoso.com. The domain contains two servers named Server1 and Server2 that run Windows Server 2012 R2. Server2 establishes an IPsec connection to Server1. You need to view which authentication method was used to establish the initial IPsec connection.

What should you do?

A. From Windows Firewall with Advanced Security, view the quick mode security association.

B. From Event Viewer, search the Application Log for events that have an ID of 1704.

C. From Event Viewer, search the Security Log for events that have an ID of 4672.

D. From Windows Firewall with Advanced Security, view the main mode security association.

Answer: D

Explanation:

Main mode negotiation establishes a secure channel between two computers by determining a set of cryptographic protection suites, exchanging keying material to establish a shared secret key, and authenticating computer and user identities. A security association (SA) is the information maintained about that secure channel on the local computer so that it can use the information for future network traffic to the remote computer. You can monitor main mode SAs for information like which peers are currently connected to this computer and which protection suite was used to form the SA.

To get to this view

In the Windows Firewall with Advanced Security MMC snap-in, expand Monitoring, expand Security Associations, and then click Main Mode.

The following information is available in the table view of all main mode SAs. To see the information for a single main mode SA, double-click the SA in the list.

Main mode SA information

You can add, remove, reorder, and sort by these columns in the Results pane:

Local Address: The local computer IP address.

Remote Address: The remote computer or peer IP address.

1st Authentication Method: The authentication method used to create the SA.

1st Authentication Local ID: The authenticated identity of the local computer used in first authentication.

1st Authentication Remote ID: The authenticated identity of the remote computer used in first authentication.

2nd Authentication Method: The authentication method used in the SA.

2nd Authentication Local ID: The authenticated identity of the local computer used in second authentication.

2nd Authentication Remote ID: The authenticated identity of the remote computer used in second authentication.

Encryption: The encryption method used by the SA to secure quick mode key exchanges.

Integrity: The data integrity method used by the SA to secure quick mode key exchanges.

Key Exchange: The Diffie-Hellman group used to create the main mode SA.

Reference: http://technet.microsoft.com/en-us/library/dd448497(v=ws.10).aspx

Exit mobile version