nerdexam
Cisco

300-630 · Question #66

Refer to the exhibit. What must be configured in the service graph to redirect HTTP traffic between the EPG client and EPG server to go through the Cisco ASA firewall?

The correct answer is B. precise filter to allow only HTTP traffic. If the contract subject filter is not set to Permit All-for instance, if it is set to Permit ICMP, Permit HTTP, or a precise filter that does not include ARP-it will work fine because ARP traffic is not infrastructure/white-paper-c11-739971.html#OnearmmodePBRconfigurationexample

Advanced ACI Policies and Integrations

Question

Refer to the exhibit. What must be configured in the service graph to redirect HTTP traffic between the EPG client and EPG server to go through the Cisco ASA firewall?

Exhibit

300-630 question #66 exhibit

Options

  • Acontract filter to allow ARP and HTTP
  • Bprecise filter to allow only HTTP traffic
  • Ccontract with no filter
  • Dpermit-all contract filter

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    83% (43)
  • C
    12% (6)
  • D
    2% (1)

Explanation

If the contract subject filter is not set to Permit All-for instance, if it is set to Permit ICMP, Permit HTTP, or a precise filter that does not include ARP-it will work fine because ARP traffic is not infrastructure/white-paper-c11-739971.html#OnearmmodePBRconfigurationexample

Topics

#service graph#contract filter#ASA firewall#HTTP redirect

Community Discussion

No community discussion yet for this question.

Full 300-630 Practice