QuestionQ83

Stateful Firewall and Screen Options

Click the Exhibit button.

Question Image

In the exhibit, eth3/1 belongs to the client-vr virtual router and eth3/2 belongs to the server-vr virtual router. Your policies allow all traffic between every zone. You want to ensure that Client1 can reach Server1.

In this scenario, which two statements are true?

Choose two
  • A By default, all interface routes are automatically imported into all virtual routers.
  • B You can configure a static route for Server1 in the client-vr virtual router that points to eth3/2.
  • C You can configure a static route for Server1 in the client-vr virtual router that points to the server-vr virtual router.
  • D You can configure a route export policy to export the route for Server1 to the client-vr virtual router.
Explanation

ScreenOS virtual routers maintain distinct route tables, so routes are not automatically shared and an interface assigned to server-vr cannot be used directly by client-vr. Inter-virtual-router routing can be provided either by a static route in client-vr that points to server-vr or by exporting the Server1 route to client-vr through virtual-router route export/import rules.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!