300-710 · Question #324
An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device wants to verify that…
The correct answer is A. Packet Capture E. Packet Tracer. To verify if specific traffic from an external vendor matches access and NAT policies on a Cisco Secure Firewall Threat Defense device, administrators should use Packet Capture and Packet Tracer tools.
Question
An external vendor is reporting that they are unable to access an ordering website hosted behind a Cisco Secure Firewall Threat Defense device. The administrator of the device wants to verify that the access policy and NAT policy are configured correctly to allow traffic from the public IP of the external vendor to TCP port 443 on the web server. Which two Cisco Secure Firewall Management Center tools must the administrator use to verify which rules the traffic from the external vendor is matching? (Choose two.)
Options
- APacket Capture
- BGenerate Troubleshooting File
- CThreat Defense CLI
- DFile Download
- EPacket Tracer
How the community answered
(23 responses)- A78% (18)
- B4% (1)
- C4% (1)
- D13% (3)
Why each option
To verify if specific traffic from an external vendor matches access and NAT policies on a Cisco Secure Firewall Threat Defense device, administrators should use Packet Capture and Packet Tracer tools.
Packet Capture allows an administrator to capture live traffic on the FTD interfaces and observe how it is processed, including pre-filter, pre-NAT, post-NAT, and post-filter stages, providing definitive proof of rule matching.
Generate Troubleshooting File collects extensive diagnostic logs and configuration details for deeper analysis, but it is not an interactive tool for verifying specific packet rule matching.
While the Threat Defense CLI has packet tracing and capture capabilities, the question specifically asks for Cisco Secure Firewall Management Center tools.
File Download is not a troubleshooting tool for verifying network policy matching on the firewall.
Packet Tracer is a simulation tool within Cisco Secure Firewall Management Center that simulates a packet's flow through the FTD, showing which Access Control Policy and NAT rules (among others) are matched and the final action taken, without needing live traffic.
Concept tested: Cisco FMC troubleshooting tools
Source: https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/troubleshooting_the_firepower_system.html
Topics
Community Discussion
No community discussion yet for this question.