QuestionQ21

Security Policies

Question Image

Referring to the exhibit, which action would you take to permit the traffic shown in the exhibit?

  • A Assign the ge-0/0/1.0 interface to a security zone.
  • B Assign the fxp0.0 interface to a security zone.
  • C Enable flow-mode processing for family mpls.
  • D Enable flow-mode processing for family inet.
Explanation

ge-0/0/1.0 is the ingress interface reported in the drop record, and its Null Zone membership causes the first packet of the flow to be dropped. Assigning that interface to a security zone allows SRX to apply the relevant zone and security-policy context to the traffic. Traffic Processing on SRX Series Firewalls Overview

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!