QuestionQ25

Troubleshooting Security Policies and Security Zones

Which two statements correctly describe the procedures a Junos security device uses to handle traffic destined for the device itself?

Choose two
  • A If the received packet is addressed to the ingress interface, then the device first performs a security policy evaluation for the junos-host zone.
  • B If the received packet is addressed to the ingress interface, then the device first examines the host -inbound-traffic configuration for the ingress interface and zone.
  • C If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation based on the ingress and egress zone.
  • D If the received packet is destined for an interface other than the ingress interface, then the device performs a security policy evaluation for the junos-host zone.
Explanation

Host-inbound traffic addressed to the receiving interface is initially checked against the host-inbound-traffic configuration at the interface or security-zone level. Traffic destined for another interface on the device is subject to a security-policy evaluation for the system-defined junos-host zone. The host-inbound-traffic setting controls which traffic may reach the device, while self-traffic policies are configured with the junos-host zone.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!