300-710 · Question #155
Within an organization's high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on
The correct answer is D. multi-instance firewalls. To segment traffic for different departments across an active-active high availability firewall environment, multi-instance firewalls are required. This allows each department's traffic to be processed by a dedicated virtual firewall instance.
Question
Within an organization’s high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?
Options
- Aredundant interfaces
- Bspan EtherChannel clustering
- Chigh availability active/standby firewalls
- Dmulti-instance firewalls
How the community answered
(26 responses)- A8% (2)
- B4% (1)
- C15% (4)
- D73% (19)
Why each option
To segment traffic for different departments across an active-active high availability firewall environment, multi-instance firewalls are required. This allows each department's traffic to be processed by a dedicated virtual firewall instance.
Redundant interfaces provide hardware fault tolerance but do not inherently segment traffic based on departments or enable an active-active processing model.
SPAN (Switched Port Analyzer) is for traffic monitoring, and EtherChannel bundles physical links for bandwidth and redundancy; neither directly provides multi-departmental firewall segmentation.
High availability active/standby firewalls mean only one firewall actively passes traffic at a time, which contradicts the requirement that 'both firewalls are passing traffic.'
Multi-instance firewalls allow multiple virtual firewall instances to run on a single physical firewall device, each operating independently with its own policies and interfaces. This enables effective traffic segmentation for different departments within an active-active HA setup, where each instance can be dedicated to a specific department's traffic.
Concept tested: Firewall virtualization and multi-instance deployment for segmentation
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa913/configuration/firewall/asa-913-firewall-config/ha-contexts.html
Topics
Community Discussion
No community discussion yet for this question.