nerdexam
Cisco

300-710 · Question #324

An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device wants to verify that…

The correct answer is A. Packet Capture E. Packet Tracer. To verify if specific traffic from an external vendor matches access and NAT policies on a Cisco Secure Firewall Threat Defense device, administrators should use Packet Capture and Packet Tracer tools.

Management and Troubleshooting

Question

An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device wants to verify that the access policy and NAT policy are configured correctly to allow traffic from the public IP of the external vendor to TCP port 443 on the web server. Which two Cisco Secure Firewall Management Center tools must the administrator use to verify which rules the traffic from the external vendor is matching? (Choose two.)

Options

  • APacket Capture
  • BGenerate Troubleshooting File
  • CThreat Defense CLI
  • DFile Download
  • EPacket Tracer

How the community answered

(23 responses)
  • A
    78% (18)
  • B
    4% (1)
  • C
    4% (1)
  • D
    13% (3)

Why each option

To verify if specific traffic from an external vendor matches access and NAT policies on a Cisco Secure Firewall Threat Defense device, administrators should use Packet Capture and Packet Tracer tools.

APacket CaptureCorrect

Packet Capture allows an administrator to capture live traffic on the FTD interfaces and observe how it is processed, including pre-filter, pre-NAT, post-NAT, and post-filter stages, providing definitive proof of rule matching.

BGenerate Troubleshooting File

Generate Troubleshooting File collects extensive diagnostic logs and configuration details for deeper analysis, but it is not an interactive tool for verifying specific packet rule matching.

CThreat Defense CLI

While the Threat Defense CLI has packet tracing and capture capabilities, the question specifically asks for Cisco Secure Firewall Management Center tools.

DFile Download

File Download is not a troubleshooting tool for verifying network policy matching on the firewall.

EPacket TracerCorrect

Packet Tracer is a simulation tool within Cisco Secure Firewall Management Center that simulates a packet's flow through the FTD, showing which Access Control Policy and NAT rules (among others) are matched and the final action taken, without needing live traffic.

Concept tested: Cisco FMC troubleshooting tools

Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/troubleshooting_the_firepower_system.html

Topics

#FTD Troubleshooting#FMC Tools#Packet Tracer#Packet Capture

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice