nerdexam
Check_Point

156-816.61 · Question #47

You are configuring source-based routing in a VSX Gateway deployment with both External and Internal Virtual Routers. Which of the following functions can't be configured for the Virtual Systems?

The correct answer is C. Anti-spoofing measures. Anti-spoofing (C) cannot be configured on Virtual Systems when source-based routing is deployed with External and Internal Virtual Routers in VSX, because the routing topology splits traffic decisions across the virtual router layer - the VS no longer has the full routing…

Managing Virtual Systems and Virtual Routers

Question

You are configuring source-based routing in a VSX Gateway deployment with both External and Internal Virtual Routers. Which of the following functions can't be configured for the Virtual Systems?

Options

  • ANetwork Address Translation
  • BVirtual System clustering
  • CAnti-spoofing measures
  • DRemote Access VPNs
  • EIntranet VPNs

How the community answered

(48 responses)
  • B
    2% (1)
  • C
    83% (40)
  • D
    10% (5)
  • E
    4% (2)

Explanation

Anti-spoofing (C) cannot be configured on Virtual Systems when source-based routing is deployed with External and Internal Virtual Routers in VSX, because the routing topology splits traffic decisions across the virtual router layer - the VS no longer has the full routing context needed to validate that packets arrived on the correct interface, which is the foundation of anti-spoofing enforcement. The distractors are all valid VS capabilities: NAT (A) is fully supported per-VS with its own rule base; Virtual System clustering (B) is supported for HA; Remote Access VPNs (D) can be enabled per-VS for remote users; and Intranet VPNs (E) - site-to-site VPNs - are also configurable at the VS level. The key insight is that source-based routing delegates layer-3 path decisions upward to the Virtual Router, which breaks the per-interface routing awareness anti-spoofing depends on.

Memory tip: "Source-based routing spoils anti-spoofing" - when the Virtual Router owns the routing table, the VS can't verify which interface a packet should have arrived on, making anti-spoofing configuration meaningless at that layer.

Topics

#Virtual Systems#Anti-spoofing#VSX features#Configuration constraints

Community Discussion

No community discussion yet for this question.

Full 156-816.61 Practice