QuestionQ33

Stateful Firewall and Screen Options

Traffic is not traversing the ScreenOS device because of an incorrectly configured policy. You must determine precisely which security policy the traffic is using.

Which two CLI commands should be used?

Choose two
  • A snoop
  • B get session
  • C debug flow basic
  • D get counter stats
Explanation

get session reports session information, including the security-policy ID associated with an existing flow. debug flow basic traces ScreenOS flow processing and reveals the policy evaluation that permits or blocks the traffic. Packet capture and interface-counter commands do not identify the policy selected for the flow.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!