nerdexam
Cisco

300-710 · Question #295

Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?

The correct answer is B. Leave BVI interface name empty.. In IRB (Integrated Routing and Bridging) mode on Cisco Secure Firewall, each bridge group is associated with a BVI (Bridge Virtual Interface), which serves as the Layer 3 gateway for that segment and enables routing between bridge groups. To create an isolated bridge group - one

Configuration

Question

Which action must be taken to configure an isolated bridge group for IRB mode on a Cisco Secure Firewall device?

Options

  • AAdd the restricted segment to the ACL.
  • BLeave BVI interface name empty.
  • CDefine the NAT pool for the blocked traffic.
  • DRemove the route from the routing table.

How the community answered

(69 responses)
  • A
    3% (2)
  • B
    88% (61)
  • C
    7% (5)
  • D
    1% (1)

Explanation

In IRB (Integrated Routing and Bridging) mode on Cisco Secure Firewall, each bridge group is associated with a BVI (Bridge Virtual Interface), which serves as the Layer 3 gateway for that segment and enables routing between bridge groups. To create an isolated bridge group - one that cannot communicate with other bridge groups or be routed to externally - you simply leave the BVI interface name field empty when configuring the bridge group. Without a BVI, the bridge group has no Layer 3 presence and cannot participate in routing, effectively isolating it. Options A, C, and D (ACL entries, NAT pools, route removal) do not achieve true isolation at the bridge-group configuration level in this context.

Topics

#IRB#Bridge Group#Firewall Configuration#Network Isolation

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice