300-710 · Question #295
Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?
The correct answer is B. Leave BVI interface name empty.. In IRB (Integrated Routing and Bridging) mode on Cisco Secure Firewall, each bridge group is associated with a BVI (Bridge Virtual Interface), which serves as the Layer 3 gateway for that segment and enables routing between bridge groups. To create an isolated bridge group - one
Question
Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?
Options
- AAdd the restricted segment to the ACL.
- BLeave BVI interface name empty.
- CDefine the NAT pool for the blocked traffic.
- DRemove the route from the routing table.
How the community answered
(69 responses)- A3% (2)
- B88% (61)
- C7% (5)
- D1% (1)
Explanation
In IRB (Integrated Routing and Bridging) mode on Cisco Secure Firewall, each bridge group is associated with a BVI (Bridge Virtual Interface), which serves as the Layer 3 gateway for that segment and enables routing between bridge groups. To create an isolated bridge group - one that cannot communicate with other bridge groups or be routed to externally - you simply leave the BVI interface name field empty when configuring the bridge group. Without a BVI, the bridge group has no Layer 3 presence and cannot participate in routing, effectively isolating it. Options A, C, and D (ACL entries, NAT pools, route removal) do not achieve true isolation at the bridge-group configuration level in this context.
Topics
Community Discussion
No community discussion yet for this question.