Maestro Expert
![]() |
![]() |
![]() |
Título del Test:![]() Maestro Expert Descripción: Maestro Expert Fecha de Creación: 2024/12/30 Categoría: Otros Número Preguntas: 113
|




Comentarios |
---|
NO HAY REGISTROS |
What Maestro component is automatically designated the SMO Master?. The SGM with the lowest member ID (the first one added to the security group.). The MDS that pushes policy to the SMO is considered the SMO Master. The first MHO configured is considered the SMO Master. The SGM with the highest member ID (the last one added to the security group.). What is a downlink interface used for?. To connect appliances to Orchestrators. To connect appliances to customer's infrastructure. To connect in between Orchestrators. To connect Orchestrators to customer's infrastructure. What type of license is required for an MHO?. The MHO requires a NGTP license. The MHO requires a VSX license. The MHO does not require a license. A license is needed for each attached SGM. What Maestro component acts as a load balancer and network switch?. Security Switching Module (SSM). Maestro Hyperscale Orchestrator (MHO). Security Group (SG). Security Gateway Module (SGM). What is an uplink interface used for?. To connect in between appliances. To connect appliances to customer's infrastructure. To connect Orchestrators to customer's infrastructure. To connect in between Orchestrators. What is a security group?. A solution for Security Gateway redundancy and Load Sharing. A set of appliances of the same model that are collectively managed by the MHO. A set of network interfaces and individual SGMs assigned to a logical group. A set of objects in SmartConsole that are responsible for enforcing an access policy. What is the Orchestrator?. Network Switch. Manager of compute and network resources, load balancer and network switch. Load balancer. None of above. What is the Correction Layer?. Correction Layer is a daemon which corrects errors on Backplane interfaces. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT. Correction Layer is a mechanism which activated in case of asymmetric routing. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute. What is the Correction Layer mechanism?. Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs. The load-balancing mechanism used by the MHO. The MHO's distribution algorithm which determines the handling SGM for a given connection. Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG. What is the maximum number of Appliances within Security group in Dual-Site configuration?. 28. 31. 15. 16. At a minimum, how many management and Uplink ports does a SG require?. Only one of the two interfaces is needed for the Security Group. Neither are required. Two of each. One each. What is the maximum number of Appliances within the same Security Group?. 31. 8. 52. 16. For the MHO-175, which ports are Management ports?. Ports 49 - 55 are Management ports. Ports 1 - 4 are Management ports. Ports 27 - 47 are Management ports. Ports 5 - 26 are Management ports. What kinds of transceivers are supported on Orchestrator MHO-140?. SFP, QSFP, QSFP28. SFP+, SFP28, QSFP. SFP, SFP+, SFP28. SFP, SFP+, QSFP, QSFP28. What happens if the SMO Master fails?. The next SGM with the current lowest SGM ID assumes the role of the SMO Master. The Backup SMO Master will take over in the event of a failure with the SMO Master. A failover will occur on the MHO and traffic will continue to pass. The Security Group will no longer pass traffic and the issue must be resolved with the SMO Master. What does the lldpctl command do?. Show all devices discovered by LLDP protocol on downlink ports. Show all devices discovered by LLDP protocol on all ports. Discover orchestrators. Show all devices discovered by LLDP protocol on uplink ports. What type of cluster can a Security Group can be compared to?. Load Sharing Active / Activ. VSLS. Active / Backup. Active / Standby. What kinds of transceivers are supported on Orchestrator MHO-170?. SFP, QSFP, QSFP28. SFP+, SFP28, QSFP. SFP, SFP+, SFP28. QSFP, QSFP28. There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intraorchestrator redundancy when using two Orchestrators?. Port 1 in Slot 2 and Port 2 in Slot 1. This configuration is not supported. Any pair of available ports. Port 1 in Slot 1 and Port 2 in Slot 1. Which licenses should be issued for the Orchestrator?. No licenses are required for Orchestrator. Depends on Software Blades enabled on connected appliances. The Orchestrator is considered a Management server, hence it's licensed the same way. The Orchestrator requires NGTX license. When security policy is installed________. All SGMs receive the security policy and one by one performs an independent policy verification. Then, all SGMs simultaneously install the policy. The SMO Master receives the policy and performs a policy verification the policy is installed on the SMO Master, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master, then the non-SMO Master SGMs install the policy. All SGMs receive the security policy and simultaneous policy installation occurs. The policy is installed on the SMO, the SMO Master broadcasts the available package, other members retrieve the new policy from the SMO Master and perform an independent policy verification, then the non- SMO Master SGMs install the policy. What cannot be learned from the output of asg monitor command?. Uptime. Port status. Security Policy status. Appliances cluster status. Maestro allows running commands globally in Expert mode by using global prefixes, such as: asg all. g_all. all. global. The ______________ command will allow users to update the specified file on all SGMs. g_update_conf_file. g_all. sed. g_cat. What happens when you make changes from Clish on the SMO Master?. The changes are synchronized to the SMS/MDS as a backup. The changes are synchronized to the MHO as a backup. Changes are only applied on the SMO Master. Changes are applied to all members in the SG. When working with Maestro, what is the difference between using Clish and gClish?. Clish commands are for testing purposes only and cannot be saved, gClish commands apply to all SG members, by default. Clish commands apply to all UP SG members, by default. gClish commands apply to all SG members, by default. Clish commands are run on the SG members. gClish commands are run on the MHO and applied to all connected SG members in a specified group. Clish commands apply only to a specific SG member. gClish commands apply to all UP SG members, by default. What cannot be learned from the output of lldpctl?. Serial number of Appliance. Appliance model. Distribution mode. Orchestrator's IP. What is the purpose of Management ports located on the Rear Panel of the Orchestrator MHO-140?. 1Gbps connectivity for Security Groups. Reserved for internal purposes. Not in use. Out-of-band interfaces for access to Orchestrator itself. Additional ports used as uplinks. What happens if you apply a hotfix using gClish?. If you apply a hotfix using gclish, it causes an outage for the entire SG as all members reboot at roughly the same time. If you apply a hotfix using gclish, each SG members installs the hotfix and reboots after waiting it's turn to do so. Logical groups "A" and "B" are created. Members of group "A" install and reboot first. Then members of group "B" does the same once reboots have finished with group "A.". If you apply a hotfix using gclish, the operation will fail because an outage would occur. What is the purpose of RJ-45 connectors located at the front panel of the Orchestrator MHO-170?. Two Out-of-band interfaces for access to Orchestrator itself. 1Gbps connectivity for Security Groups. Out-of-band interface for access to Orchestrator itself and Serial Console connector. Reserved for internal purposes. Not in use. What does asg monitor command do?. This command does not exist. Monitor health status of entire system. Monitor traffic on Appliances in Security Group. Show real-time cluster status of Appliances in Security Group. What will happen in case of NAT of the traffic passing through Management network?. This traffic will not pass correction, since it will be dropped. Orchestrator will disable NAT and traffic will pass with no issue. Since Management traffic is always going to SMO, it will take a care for Correction Layer and will redistribute traffic to other Appliances. This traffic will pass with no inspection. Which distribution mode assigns packets to an SGM based solely on the packet destination IP?. User mode. Manual mode. Network mode. Auto-topology mode. When a VPN tunnel is formed with a Maestro SGM,. The receiving SGM makes an encryption decision. The SGM then syncs the traffic to two backup SGMs: one for clear traffic and one for encrypted traffic. SGM 1 analyzes the policy and topology. If encryption is required, it calculates the tunnel owner's IP address. SGM 1 sends a clear packet to the tunnel owner. SGM 2 is now the connection and tunnel owner. The MHO handles the IKE before distributing the traffic to a SGM to handle all encrypted traffic. This helps to prevent any issues with the correction layer. The MHO distributes copies of the packets to two different SGMs because SGM 1 will handle the clear traffic IKE exchange packets, while SGM2 handles encrypted packets. What is the default Distribution mode?. Auto-topology. User. Manual-General. Network. Layer 4 distribution is enabled by default in Maestro. Which is not a scenario when you would want to leave this enabled?. When there is a large number of source ports in use by protocols such as HTTP, HTTPS, and DNS. When dynamic routing protocols, such as BGP or OSPF are used. When there is a heavy imbalance of traffic between the SGMs that are members of the same SG. When the SG is NATing a very high percentage of traffic passing through it. What command can be run to show which SGM is selected to receive traffic?. g_tcpdump. asg monitor. dxl calc. asg calc. Is it possible to define distribution mode per interface?. Yes, only for downlink interfaces. No, only for the Security Group. Yes, only for uplink interfaces. Yes, for both uplink and downlink interfaces. There are two appliances within the same Security Group. One of them is connected by One downlink only, another one by Two downlinks. Assuming there's no NAT and no VPN, what would be proportion of traffic distribution done by Orchestrator?. 100%/0%. 33%/66%. 50%/50%. 66%/33%. In case of Correction, where is information about Owner stored?. In Correction table of Target Appliance. In Connection tables of all Appliances participating in Correction Layer flow. In Correction tables of all Appliances participating in Correction Layer flow. In Connection table of Target Appliances. While looking at your system's correction statistics, you notice you have a correction rate approaching 100 percent. Is this a problem?. A correction rate above 90 percent indicates a need to disable Layer 4 Distribution. A correction rate approaching 100 percent of all connections is unusual. This is a cause for concern because the SGMs may fail to process traffic. If correction rates are higher than 80 percent, latency is expected. In some scenarios, a correction rate approaching 100 percent of all connections is not unusual. This is not usually a cause for concern as the correction mechanism is fast and efficient. There is a Security group of 10 Appliances and all of them are up and running. How many Appliances within a Security Group keep the same connection in its connection table in case of NAT?. Between 2 and 4. All 10. 2. 3. Which command do you use to find bottlenecks in the system that are affecting performance, even functionality in some cases?. asg stat -v. asg diag verify. asg perf -v. asg monitor. What is the command 'asg diag' used for?. Asg diag used for system diagnostics on Chassis only. It does not exist on Maestro. Asg diag is used for system backup. Asg diag is used for system diagnostics. Asg diag is used for creating traffic flow diagrams. HealthCheck Point _____. is a self-updatable suite of tools for MHOs with the capability to assess the health of the system and provide a timeline of critical and informative events that might have occurred in a production system. performs a system health check and is meant to replace both a CPInfo and the health check script. can be used to let you visualize the Firewall topology for the SG and view live statistics, which includes throughput, problem notes, and CPU utilization. is a self-updatable suite of tools for SGMs with the capability to assess the health of the system, visualize the Firewall topology, provide a timeline of critical and informative events that might have occurred in a production system. What command should be used for collecting diagnostic information about the orchestrator?. cpinfo. asg perf -v. cpview. orch_info. The core four manual diagnostic tools include: asg diag verify, asg perf -v, orch_stat -all, and. asg diag verify. cpinfo. hcp -r all. asg stat -v. Which feature is used to force trusted non-F2F traffic into the fully accelerated path for handling by SecureXL. Fast Accelerator. hypersync. rate limiting. SecureXL. Splitter cannot be used _______. To connect single port on orchestrator to the same Appliance. To connect single port on orchestrator to multiple port on external switch. To connect single port on Appliance to multiple ports on the orchestrator. To connect single port on orchestrator to multiple Appliances. What is the purpose of g_tcpdump command?. Collects traffic dump from all Active Appliances within Security Group. Collects traffic dump from CIN network. Collects traffic dump from Sync network. The same as tcpdump, just on Scalable Platform. What is the throughput penalty of Security Group?. Depends on the type of Appliance. 1% per member. 10% per Security Group with no relation to the number of members. 5% per member. To display processes that are consuming excessive system resources, users should use the_____ command. asg perf -v. asg stat -v. top. asg_perf_hogs. Logs without a dedicated log file can be found in. /var/log/junk.log.dbg. /var/log/messages. $RTDIR/log/junk.log. $FWDIR/log/fw.log. The drop_monitor command is useful for. Monitoring Check Point code drops. Viewing all interface drops such as RX-ERR, RX-DRP, and RX-OVR. Viewing all drops by Check Point code or the Gaia OS, such as RX-DRP, RX-ERR, and Gaia OS drops. Showing the system temperature in real-time for multiple components, such as CPU, fan, and SSDs. Possibilities for a failure in a single SGM of a Security Group include. A change was made with clish instead of gClish, causing the SGM to handle traffic differently than the other SGMs. SecureXL is not enabled on the SGM. An administrator imported a hotfix into the CPUSE repository of a single SGM. There are too many active SGMs in the SG. There are two 10Gbps dual-port NIC installed on a 6800 appliance. Which interfaces should be connected to Orchestrator 1 for downlinks' intra-orchestrator redundancy when using two Orchestrators?. Any pair of available ports. Port 1 in Slot 1 and Port 1 in Slot 2. Port 1 in Slot 1 and Port 2 in Slot 1. Port 1 in Slot 2 and Port 2 in Slot 1. What is one benefit of a Dual MHO environment?. Dual MHOs provide redundancy to the Maestro environment by increasing throughput by at least 50 percent. Dual MHOs allow better synchronization to occur between SGMs. Dual MHOs allow additional SGMs to be added to the SG. Dual MHOs can be used to achieve increased scalability and redundancy.. What cannot be a reason for "Failed to get remote orchestrator interfaces" error message, when clicking on "Orchestrator" in WebUI. Remote orchestrator has no empty interfaces. Single orchestrator environment, but configured Orchestrator amount is 2. One orchestrator only, but Orchestrator amount is 2 or no Sync in between orchestrators. No Sync between orchestrators. What can be learned from the output of sx_api_ports_dump.py command?. Information about backplane bonds. Information about Security Groups. Orchestrator port status. Information about downlink ports only. In a dual MHO environment, MHO1 and MHO2 are connected to the SGM line cards in which way?. MHO1 and MHO2 are connected to the SGMs using the Sync cable. MHO1 and MHO2 are connected to the line cards in any order administrators see fit. MHO 1 is connected to the even-numbered ports, while MHO2 is connected to odd-numbered ports. MHO 1 is connected to the odd-numbered ports, while MHO2 is connected to even-numbered ports. In what mode do MHOs process traffic?. MHOs process traffic in load sharing mode. MHOs process traffic in Active-Standby mode. MHOs process traffic in Active-Active mode. MHOs process traffic in VSLS mode. Which command should be used to restart Orchestrator service only?. orchd restart. reboot. service orchestrator restart. cpstop; cpstart. Where should sx_api_ports_dump.py command be ran?. Management server. Security Group. Orchestrator. SMO Appliance. Complete the sentence: Dual Orchestrators work as.______. Load Sharing cluster. Active-Active cluster. Active - Standby cluster. Hot-Swap RAID. In a Maestro Dual Site environment, what is the definition of the term Active Site. The Active Site is the site that is not handling any traffic for the specific SG, but its connections are synced to its SGMs from the MHOs to be ready in the event of a failover. The Active Site is the site where the SMO Master exists. There is no such thing as an active site. In a Dual Site environment, traffic is load balanced. The Active Site is the site currently handling the enforcement on traffic passing for a specific SG. Connections are synced within the SGMs in the Active Site. How many orchestrators may Dual-Site include?. 2 or 4. 2. 1. Only 4. Multiple SGs can exist in a Dual Site environment. Each SG can be configured in one of three ways. Which is not one of those ways?. Two MHOs connected to two MHOs via load balancers. Two MHOs at same site connected to remote site MHOs via two different switches. Two MHOs at same site connected to remote site MHOs via single switch. Direct connectivity between Remote Site MHOs. Which command is used to set the number of sites in a Maestro environment?. set maestro orchestrator-site-amount. set maestro configuration orchestrator-site-amount. set maestro configuration orchestrator-site-number. set maestro configuration orchestrator-site-id. What is the difference between Dual-Site and Dual-Room?. Dual-Room is a kind of Dual-Site deployment within the same building. Dual-Room is Active / Standby and Dual-Site is Active / Active. Dual-Room is a Single-Site deployment where all Appliances are connected to both orchestrators. They are the same. How does HyperSync work in a Dual Site environment?. Each active connection has two local backups (on the local site) and a third backup connection on the second site (remote site.). Each active connection has a backup connection on the second site (remote site.). Each active connection has a local backup (on the local site) and a second backup connection on the second site (remote site.). Each active connection has a local backup (on the local site) and a second backup connection on each of the MHOs. What is the max amount of Orchestrators in Dual-site setup?. 2 per Security Group. 4 per Security Group. 2. 4. After you import the R81.10 software package, what do you use to verify that it is possible to upgrade an MHO or SG?. Run HCP. One of the tests will list upgrade eligibility status for the MHO or SG. Run the Pre-Upgrade Verifier to make sure it is possible to upgrade. Nothing. CPUSE will run a verification during the upgrade process to ensure the package is compatible. The package is verified during the import process and a warning or error will be displayed at that time. During an upgrade, Is Multi-Version Clustering (MVC) supported?. No. Maestro does not support MVC because ClusterXL is disabled during an upgrade. No, Maestro does not support MVC. Maestro supports MVC or full connectivity upgrade as of R80.40. Yes, MVC is supported as of R81 for Maestro. Do all MHOs need to be upgraded before starting the SGM upgrades?. During the upgrade process all SGMs should be upgraded before upgrading all of the MHOs. A minimum of one of the MHOs should be upgraded before starting the SGM upgrades. However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHO. All MHOs must first be upgraded before starting the SGM upgrades However, there is no requirement to upgrade all the SGMs during the same maintenance window as the MHOs. MHOs do not need to be upgraded at all because Maestro supports the use of different versions between the MHOs and SGMs. Which blade configuration files should be backed up on the SG if upgrading from R80.30SP or earlier?. IPS configuration files. fwkern.conf files. VPN configuration files. Mobile Access configuration files. What is the Correction Layer?. Correction Layer is a daemon which corrects errors on Backplane interfaces. Correction Layer is a mechanism which handles asymmetric connections in multi-appliance system. For example, in case of NAT. Correction Layer is a mechanism which activated in case of asymmetric routing. Correction Layer is a Layer of GAIA OS which corrects misspelled commands and allows them to execute. Which is a key driver for Scalable Platform?. On-demand flexibility in reconfiguration. HyperSync provides scalability by reducing overhead. Resiliency is achieved through the use of redundant hardware. Cloud-level security by maximizing capabilities of existing hardware. What is a downlink interface used for?. To connect appliances to Orchestrators. To connect appliances to customer's infrastructure. To connect in between Orchestrators. To connect Orchestrators to customer's infrastructure. The SGM with the lowest member ID (the first one added to the security group.). The MDS that pushes policy to the SMO is considered the SMO Master. The first MHO configured is considered the SMO Master. The SGM with the highest member ID (the last one added to the security group.). What Maestro component is automatically designated the SMO Master?. What type of license is required for an MHO?. The MHO requires a NGTP license. The MHO requires a VSX license. The MHO does not require a license. A license is needed for each attached SGM. What is a security group?. A solution for Security Gateway redundancy and Load Sharing. A set of appliances of the same model that are collectively managed by the MHO. A set of network interfaces and individual SGMs assigned to a logical group. A set of objects in SmartConsole that are responsible for enforcing an access policy. What is the Correction Layer mechanism?. Ensures asymmetric traffic is handled properly, especially in the case of NAT or VPNs. The load-balancing mechanism used by the MHO. The MHO's distribution algorithm which determines the handling SGM for a given connection. Enforces the access policy on the SGMs and synchronizes the enforcement verdict to other SGMs in the SG. What is an uplink interface used for?. To connect in between appliances. To connect appliances to customer's infrastructure. To connect Orchestrators to customer's infrastructure. To connect in between Orchestrators. What is the Orchestrator?. Network Switch. Manager of compute and network resources, load balancer and network switch. Load balancer. None of above. What kinds of transceivers are supported on Orchestrator MHO-170?. SFP, QSFP, QSFP28. SFP+, SFP28, QSFP. SFP, SFP+, SFP28. QSFP, QSFP28. There are two 10Gbps dual-port NICs and one 40Gbps NIC installed on a 23800 Appliance in slots 1, 2 and 3 accordingly. Which interfaces should be connected to Orchestrator 1 for downlinks' intraorchestrator redundancy when using two Orchestrators?. Port 1 in Slot 2 and Port 2 in Slot 1. This configuration is not supported. Any pair of available ports. Port 1 in Slot 1 and Port 2 in Slot 1. What is the purpose of interface bonding?. A bond interface can be configured for high availability redundancy. A bond interface is used for passing synchronization traffic between the SGMs. For load sharing which increases connection throughput above that which is possible using one physical interface. A bond interface can be configured for high availability redundancy or for load sharing which increases connection throughput above that which is possible using one physical interface. What is the maximum number of Appliances within the same Security Group?. 31. 8. 52. 16. What type of cluster can a Security Group can be compared to?. Load Sharing Active / Active. VSLS. Active / Backup. Active / Standby. On the MHO, to view connected ports and their functions, use the following command: asg_ifconfig. show ports. orch_stat -c. orch_stat -p. What command will be used for updating fwkern.conf file on all Appliances within Security Group?. vi. g_all update_conf_file. g_update_kernel. g_update_conf_file. Each morning at 1:00 am, a series of automatic diagnostics on all the SGMs runs by automatic execution of which command?. hcp -r all. asg diag list. asg diag verify. asg perf -v. Common Layer 1 issues include. Routing. Distribution. MAC addresses. Loose or bad cables. The __________command can be used during an upgrade to verify that the upgraded SGMs have returned to UP status before upgrading other SGMs. asg monitor. cpview. asg perf -v. watch asg stat -v. For a VSX configuration – Which statement is wrong?. All Virtual Systems exist on the SMO. All Virtual Systems exist on all Appliances. VSX configuration is the same on all Appliances within the same Security Group. Each Appliance owns different Virtual Systems. One single Appliance supports 1M concurrent connections. How many concurrent connections will support Security Group of 2 Appliances?. 2M. 500K. 4M. 1M. Which is a valid requirement for a supported Maestro appliance?. 10GBps and 40Gbps or 100Gbps card with double-VLAN and LLDP support. At least one 10GBps line card. Nothing special as Maestro supports any Check Point appliance. Line card with double-VLAN and LLDP support. Orchestrator should be defined in SmartConsole as: Orchestrator is not defined in SmartConsole. Check Point host. Security Gateway. Hsot. What does the command'g_all' do?. It's followed by other command and execute it on all active Appliances within Security Group. It's followed by other command and execute it on all Appliances connected to Orchestrator. Switches all Appliances to Global mode. Bring up all Appliances. When running asg perf -v in a Dual-Site environment, we can see only Appliances from one of the sites. That means we’re working in: VSLS mode. Active /Active. Active / Standby HA mode. This is not Dual-Site, in Dual-Site we always see Appliances from both sites. Which file on Appliance includes information about Security Group?. /etc/chassisdb.json. /etc/sgdb.json. /etc/smodb.json. /etc/distutil.json. What is a Security Group?. Logical group of computer and network resources. Group of security administrators. Group of security gateways. Group of appliances with enabled NGTX software blades. On MHO-170 – In default configuration, what are GAIA names of Security Group Management ports?. eth1-Mgmt1 and eth1-Mgmt2. eth1-Mgmt1 and eth2-Mgmt1. eth1-Mgmt1 and eth1-Mgmt3. eth1-Mgmt3 and eth1-Mgmt4. What is the difference between Dual-Site and Multi-Room?. Multi-Room is a Single-Site deployment where all Appliances are connected to both orchestrators. Multi-Room is a kind of Dual-Site deployment within the same building. Multi-Room is Active / Standby and Dual-Site is Active / Active. This is the same. What is the minimal requirement for a Security Group?. 1 Appliance and 1 management port. 2 Appliances and 2 ports. 1 Appliance and 1 administrator with Multi-Domain admin permissions. None, it may be empty. What is the default range of physical ports for downlinks on Orchestrator MHO-170?. 3 - 16. 17 - 31. 25 - 32. 1 - 16. In order to set Site (chassis) priority per VS, following command should be used: From given VS context: set chassis high-availability vs chassis_priority. From given VS0 context: set chassis high-availability vs chassis_priority. From any VS context: set chassis high-availability vs chassis_priority. From VS0 context: set chassis high-availability vs chassis_priority. What kind of cluster Dual-Site can be compared to?. Active-Standby or VSLS. VSLS only. Active-Active. Active-Standby only. What cannot be a reason for DETACHED status of Appliance when running asg monitor command?. Appliance reboots. Appliance is a member of Security Group, but currently disconnected. Appliance installed with R80.20. There's an issue with Downlink cable. What is the Iterator process?. Iterator is the process that simulates distribution in case of Appliance failure. Iterator is the process that follow Appliance recovery and simulates what was a distribution if recovered Appliance was alive. Iterator is the process that runs on the Orchestrator and calculates a distribution in case of Appliance failure. Iterator is the process that runs on the Orchestrator and calculates a distribution in case of Appliance recovery. Which setting is required in order to connect an appliance with 40Gbps downlink interface and DAC to the Orchestrator MHO-140?. On Orchestrator: Change QSFP mode from 100Gbps to 40Gbps. On Orchestrator: Change port type from uplink to downlink. On Appliance: Change a port speed to 10Gbps. No change required. In case of VSX: What is the right command to see overall performance details of all Appliances within the Security Group and all Virtual Systems?. asg pert -v -p. asg pert -vs all -v -vv. asg pert -v. asg pert -vs enabled -p. Complete the sentence: When using a Break-out cable... All tails of the break-out cable must represent the same type of ports. All tails of the break-out cable must represent uplinks. Each tail of the break-out cable represent an independent port. All tails of the break-out cable must represent downlinks. |