QuestionQ91

Stateful Firewall and Screen Options

Click the Exhibit button.

Question Image

Traffic with source IP address 192.168.100.60, destination IP address 8.8.8.8, and destination port 80 passes through the ScreenOS device. The inbound zone is Trust, and the outbound zone is Untrust.

Based on the policy configuration in the exhibit, what happens to this traffic?

  • A The traffic is denied by default policy.
  • B Traffic is denied by policy ID 3.
  • C Traffic is permitted by the global policy.
  • D Traffic is permitted by policy ID 2.
Explanation

Policies 2 and 3 apply only to source address 192.168.100.50/32, not 192.168.100.60. With no matching Trust-to-Untrust policy, the global policy is evaluated. Its Any source and destination criteria and HTTP service match this port-80 traffic, so it permits the session. Juniper documents that global policies are considered after interzone policies when no regular policy matches.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!