nerdexam
Citrix

1Y0-351 · Question #279

Scenario: A NetScaler Engineer is configuring a NetScaler that has three interfaces. The first interface is connected to the internal network, the second interface is connected to the DMZ1- network…

The correct answer is C. add ns pbr PBR1 ALLOW -srcIP = 10.20.20.0-10.20.20.255 -destIP != 10.20.20.0-10.20.20.255 -. See the full explanation below for the reasoning.

Question

Scenario: A NetScaler Engineer is configuring a NetScaler that has three interfaces. The first interface is connected to the internal network, the second interface is connected to the DMZ1- network, and the third interface is connected to the DMZ2-network. DMZ1 and DMZ2 networks are behind different firewalls, and both firewalls are sending traffic through network address translation (NAT) to the DMZ networks. The default route is to the gateway on the DMZ1-network. DMZ1: 10.10.10.0/24 (Gateway: 10.10.10.1) DMZ2: 10.20.20.0/24 (Gateway: 10.20.20.1) Internal: 192.168.0.0/24 (Gateway: 192.168.0.1) Internet traffic reaches the virtual servers located in DMZ1 but NOT the virtual servers located in DMZ2. Which policy-based route (PBR) would resolve the issue?

Options

  • Aadd ns pbr PBR1 ALLOW -srcIP = 10.20.20.0-10.20.20.255 -destIP != 10.20.20.0-10.20.20.255 -
  • Badd ns pbr PBR1 ALLOW -srcIP != 10.20.20.0-10.20.20.255 -destIP = 10.20.20.0-10.20.20.255 -
  • Cadd ns pbr PBR1 ALLOW -srcIP = 10.20.20.0-10.20.20.255 -destIP != 10.20.20.0-10.20.20.255 -
  • Dadd ns pbr PBR1 ALLOW -srcIP != 10.20.20.0-10.20.20.255 -destIP != 10.20.20.0- 10.20.20.255 -

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    9% (3)
  • C
    81% (26)
  • D
    6% (2)

Community Discussion

No community discussion yet for this question.

Full 1Y0-351 Practice