nerdexam
Cisco

300-710 · Question #76

A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet. How is this accomplished on an FTD device in routed mode?

The correct answer is C. by using a BVI and create a BVI IP address in the same subnet as the user segment. A Bridge Virtual Interface (BVI) enables FTD - even in routed mode - to bridge two physical interfaces at Layer 2 while assigning the BVI an IP address in the same subnet as the user segment. This allows the firewall to inspect traffic transparently without the endpoints needing

Configuration

Question

A network engineer is extending a user segment through an FTD device for traffic inspection without creating another IP subnet. How is this accomplished on an FTD device in routed mode?

Options

  • Aby leveraging the ARP to direct traffic through the firewall
  • Bby assigning an inline set interface
  • Cby using a BVI and create a BVI IP address in the same subnet as the user segment
  • Dby bypassing protocol inspection by leveraging pre-filter rules

How the community answered

(31 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    81% (25)
  • D
    13% (4)

Explanation

A Bridge Virtual Interface (BVI) enables FTD - even in routed mode - to bridge two physical interfaces at Layer 2 while assigning the BVI an IP address in the same subnet as the user segment. This allows the firewall to inspect traffic transparently without the endpoints needing to be re-addressed or placed into a new subnet. ARP manipulation (A) does not achieve transparent inspection. Inline sets (B) are used in transparent/IPS mode, not routed mode with this use case. Pre-filter rules (D) bypass inspection rather than enable it.

Topics

#FTD#Bridged Virtual Interface (BVI)#Network Configuration#Routed Mode

Community Discussion

No community discussion yet for this question.

Full 300-710 Practice