300-710 · Question #272
An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the
The correct answer is A. IPsec. To encrypt information exchanged over the failover link between Cisco FTD devices in a high availability pair, IPsec is the protocol that supports this secure communication.
Question
An engineer is configuring two new Cisco FTD devices to replace the existing high availability firewall pair in a highly secure environment. The information exchanged between the FTD devices over the failover link must be encrypted. Which protocol supports this on the Cisco FTD?
Options
- AIPsec
- BSSH
- CSSL
- DMACsec
How the community answered
(46 responses)- A93% (43)
- C4% (2)
- D2% (1)
Why each option
To encrypt information exchanged over the failover link between Cisco FTD devices in a high availability pair, IPsec is the protocol that supports this secure communication.
IPsec provides encryption for the stateful failover communication that occurs between active and standby Cisco FTD devices over the dedicated failover link. This ensures the confidentiality, integrity, and authenticity of critical synchronization and control plane traffic in a high availability setup.
SSH is used for secure remote shell access and management, not for encrypting high availability failover traffic between firewalls.
SSL/TLS is typically used for securing application-layer protocols like HTTPS, not for encrypting the underlying failover link between network devices.
MACsec provides Layer 2 encryption for point-to-point Ethernet links but is not the primary protocol used by Cisco FTD for encrypting failover link communication.
Concept tested: Cisco FTD HA failover link encryption
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-70/high_availability.html
Topics
Community Discussion
No community discussion yet for this question.