400-007 · Question #34
Which two characteristics apply to firewall transparent mode operations in a firewall solution design? (Choose two.)
The correct answer is C. Multicast traffic can traverse the firewall. D. OSPF adjacencies can be established through the firewall. A transparent mode firewall operates as a Layer 2 bridge, allowing Layer 3 protocols such as OSPF and multicast to pass through without requiring IP addressing changes or acting as a routed hop.
Question
Which two characteristics apply to firewall transparent mode operations in a firewall solution design? (Choose two.)
Options
- AChanges in the existing IP addressing and subnets are required
- BThe firewall can participate actively on spanning tree.
- CMulticast traffic can traverse the firewall.
- DOSPF adjacencies can be established through the firewall
- EThe firewall acts like a router hop in the network.
How the community answered
(46 responses)- A15% (7)
- B2% (1)
- C74% (34)
- E9% (4)
Why each option
A transparent mode firewall operates as a Layer 2 bridge, allowing Layer 3 protocols such as OSPF and multicast to pass through without requiring IP addressing changes or acting as a routed hop.
Transparent mode is specifically designed to eliminate the need for IP addressing changes - the firewall is inserted as a Layer 2 device without requiring subnet modifications.
A transparent firewall passes STP BPDUs to allow spanning tree to function across it, but it does not originate BPDUs or participate in the root bridge election as an active STP bridge.
Because a transparent mode firewall operates at Layer 2 and forwards frames rather than routing packets, multicast traffic is passed through it without requiring the firewall to function as a multicast router or alter addressing.
OSPF hello packets and adjacency traffic are forwarded at Layer 2 through a transparent firewall, so routers on both sides can establish full OSPF neighbor relationships as if the firewall were not present in the path.
Transparent mode is explicitly Layer 2 and does not act as a router hop - it does not decrement TTL and does not appear as a hop in traceroute output.
Concept tested: Transparent firewall Layer 2 bridge mode characteristics
Source: https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/98156-asa-transparent-mode.html
Topics
Community Discussion
No community discussion yet for this question.