nerdexam
Cisco

300-320 · Question #549

How to apply firewall mode that shares ACL NAT?

The correct answer is A. Router mode. Routed mode (Router mode) is the correct answer. In routed mode, the firewall operates as a Layer 3 device (a routed hop in the network), and it fully supports both ACLs and NAT. Transparent mode makes the firewall act as a Layer 2 bridge (a 'bump in the wire') - it does not…

Security Services

Question

How to apply firewall mode that shares ACL NAT?

Options

  • ARouter mode
  • BTransparent

How the community answered

(41 responses)
  • A
    90% (37)
  • B
    10% (4)

Explanation

Routed mode (Router mode) is the correct answer. In routed mode, the firewall operates as a Layer 3 device (a routed hop in the network), and it fully supports both ACLs and NAT. Transparent mode makes the firewall act as a Layer 2 bridge (a 'bump in the wire') - it does not have IP addresses on its interfaces and has very limited or no support for NAT, making it unsuitable when NAT and ACLs must be shared on the same firewall interface.

Topics

#firewall modes#routed mode#NAT#ACL

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice