300-710 · Question #334
An engineer must create an access control policy on a Cisco Secure Firewall Threat Defense device. The company has a contact center that utilizes VoIP heavily, and it is critical that this traffic…
The correct answer is B. trust. The 'Trust' action in a Cisco Secure Firewall access control policy bypasses the Snort inspection engine entirely for matching traffic. For latency-sensitive, high-volume VoIP (RTP/SIP) traffic, deep packet inspection by Snort adds processing delay and jitter that can degrade…
Question
An engineer must create an access control policy on a Cisco Secure Firewall Threat Defense device. The company has a contact center that utilizes VoIP heavily, and it is critical that this traffic is not impacted by performance issues after deploying the access control policy. Which access control action rule must be configured to handle the VoIP traffic?
Options
- Ablock
- Btrust
- Cmonitor
- Dallow
How the community answered
(55 responses)- A2% (1)
- B91% (50)
- C4% (2)
- D4% (2)
Explanation
The 'Trust' action in a Cisco Secure Firewall access control policy bypasses the Snort inspection engine entirely for matching traffic. For latency-sensitive, high-volume VoIP (RTP/SIP) traffic, deep packet inspection by Snort adds processing delay and jitter that can degrade call quality. By applying a 'Trust' rule specifically for VoIP traffic, the firewall forwards the packets without sending them through the IPS/IDS engine, preserving performance. 'Block' (A) would drop VoIP traffic. 'Monitor' (C) logs the traffic but continues processing through other rules, still passing through Snort. 'Allow' (D) permits traffic but still subjects it to full inspection by associated intrusion and file policies, which can impact VoIP performance.
Topics
Community Discussion
No community discussion yet for this question.