300-710 · Question #426
Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one…
The correct answer is B. inbound access rule that allows ICMP Type 3 from outside. When the firewall drops packets to an unused or mistyped port, it returns ICMP “destination unreachable” (Type 3) messages. If those ICMP replies are blocked by the access policy, the client never sees the error and must wait for the TCP session to time out. Permitting ICMP…
Question
Refer to the exhibit. Users attempt to connect to numerous external resources on various TCP ports. If the users mistype the port, their connection closes immediately, and it takes more than one minute before the connection is torn down. An engineer manages to capture both types of connections as shown in the exhibit. What must the engineer configure to lower the timeout values for the second group of connections and resolve the user issues?
Exhibit
Options
- Aoutbound access rule that allows the entire ICMP protocol suite
- Binbound access rule that allows ICMP Type 3 from outside
- Cinbound access rule that allows TCP reset packets from outside
- Doutbound access rule with the Block with reset action
How the community answered
(27 responses)- A11% (3)
- B78% (21)
- C7% (2)
- D4% (1)
Explanation
When the firewall drops packets to an unused or mistyped port, it returns ICMP “destination unreachable” (Type 3) messages. If those ICMP replies are blocked by the access policy, the client never sees the error and must wait for the TCP session to time out. Permitting ICMP Type 3 from the outside lets clients receive the unreachable and tear down the connection immediately.
Topics
Community Discussion
No community discussion yet for this question.
