300-710 · Question #45
Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)
The correct answer is B. Bridge groups are supported in both transparent and routed firewall modes. E. Each directly connected network must be on the same subnet. B is correct: Bridge groups are supported in both transparent and routed firewall modes in FTD. In transparent mode, the firewall acts as a Layer 2 bridge. In routed mode, a Bridge Virtual Interface (BVI) can be assigned an IP address to route between bridge-group member…
Question
Which two statements about bridge-group interfaces in Cisco FTD are true? (Choose two.)
Options
- AThe BVI IP address must be in a separate subnet from the connected network.
- BBridge groups are supported in both transparent and routed firewall modes.
- CBridge groups are supported only in transparent firewall mode.
- DBidirectional Forwarding Detection echo packets are allowed through the FTD when using bridge-
- EEach directly connected network must be on the same subnet.
How the community answered
(21 responses)- B90% (19)
- C5% (1)
- D5% (1)
Explanation
B is correct: Bridge groups are supported in both transparent and routed firewall modes in FTD. In transparent mode, the firewall acts as a Layer 2 bridge. In routed mode, a Bridge Virtual Interface (BVI) can be assigned an IP address to route between bridge-group member interfaces. E is correct: All interfaces within a bridge group must reside on the same IP subnet, because the bridge group operates at Layer 2 and the BVI IP must belong to that shared subnet. A is incorrect: The BVI IP must be on the same subnet as the connected hosts-not a separate one. C is incorrect because bridge groups work in routed mode as well. D is incorrect: BFD echo packets are not automatically permitted through the FTD in a bridge-group configuration; BFD is not a special exception.
Topics
Community Discussion
No community discussion yet for this question.