nerdexam
Cisco

300-710 · Question #351

Refer to the exhibit. A company is deploying a pair of Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pair with a failover li

The correct answer is C. Connect and configure a stateful link and then deploy the changes.. In a failover configuration with Cisco Secure Firewall Threat Defense (FTD) devices, ensuring that users on the internal network can continue to communicate with outside devices if the primary device (FTD1) fails requires the implementation of a stateful failover link. The statef

Deployment

Question

Refer to the exhibit. A company is deploying a pair of Cisco Secure Firewall Threat Defense devices named FTD1 and FTD2. FTD1 and FTD2 have been configured as an active/standby pair with a failover link but without a stateful link. What must be implemented next to ensure that users on the internal network still communicate with outside devices if FTD1 fails?

Exhibits

300-710 question #351 exhibit 1
300-710 question #351 exhibit 2

Options

  • ADisable port security on the switch interfaces connected to FTD1 and FTD2.
  • BSet maximum secured addresses to two on the switch interfaces on FTD1 and FTD2.
  • CConnect and configure a stateful link and then deploy the changes.
  • DConfigure the spanning-tree PortFasI feature on SW1 and FTD2.

How the community answered

(17 responses)
  • B
    6% (1)
  • C
    94% (16)

Explanation

In a failover configuration with Cisco Secure Firewall Threat Defense (FTD) devices, ensuring that users on the internal network can continue to communicate with outside devices if the primary device (FTD1) fails requires the implementation of a stateful failover link. The stateful failover link allows the secondary device (FTD2) to maintain session information and state data, ensuring seamless failover and minimizing disruptions. Steps to implement a stateful failover link: Physically connect a stateful failover link between FTD1 and FTD2. Configure the stateful failover link in the FMC. Ensure that both devices are properly synchronized and that stateful failover is enabled. Deploy the changes to both FTD devices. By configuring a stateful link, the secondary FTD can take over active sessions without requiring users to re-establish their connections, thus ensuring continuous communication.

Topics

#Cisco Secure Firewall Threat Defense (FTD)#High Availability (HA)#Active/Standby Failover#Stateful Link

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice