nerdexam
CompTIA

CAS-002 · Question #830

VPN users cannot access the active FTP server through the router but can access any server in the data center. Additional network information: DMZ network - 192.168.5.0/24 (FTP server is…

The correct answer is A. Add a permit statement to allow traffic from 192.168.5.0/24 to the VPN network. Active FTP requires the server to initiate a data channel connection back to the client, but the router ACL only permits return traffic from the DMZ gateway (192.168.5.1/32), not from the FTP server at 192.168.5.11, blocking active FTP data transfers from VPN users.

Technical Integration of Enterprise Components

Question

VPN users cannot access the active FTP server through the router but can access any server in the data center. Additional network information:

DMZ network - 192.168.5.0/24 (FTP server is 192.168.5.11) VPN network - 192.168.1.0/24 Datacenter - 192.168.2.0/24 User network - 192.168.3.0/24 HR network - 192.168.4.0/24\ Traffic shaper configuration:

VLAN Bandwidth Limit (Mbps) VPN 50 User 175 HR 250 Finance 250 Guest 0 Router ACL:

Action SourceDestination Permit 192.168.1.0/24 192.168.2.0/24 Permit 192.168.1.0/24 192.168.3.0/24 Permit 192.168.1.0/24 192.168.5.0/24 Permit 192.168.2.0/24 192.168.1.0/24 Permit 192.168.3.0/24 192.168.1.0/24 Permit 192.168.5.1/32 192.168.1.0/24 Deny 192.168.4.0/24 192.168.1.0/24 Deny 192.168.1.0/24 192.168.4.0/24 Deny any any Which of the following solutions would allow the users to access the active FTP server?

Options

  • AAdd a permit statement to allow traffic from 192.168.5.0/24 to the VPN network
  • BAdd a permit statement to allow traffic to 192.168.5.1 from the VPN network
  • CIPS is blocking traffic and needs to be reconfigured
  • DConfigure the traffic shaper to limit DMZ traffic
  • EIncrease bandwidth limit on the VPN network

How the community answered

(24 responses)
  • A
    58% (14)
  • B
    13% (3)
  • C
    4% (1)
  • D
    21% (5)
  • E
    4% (1)

Why each option

Active FTP requires the server to initiate a data channel connection back to the client, but the router ACL only permits return traffic from the DMZ gateway (192.168.5.1/32), not from the FTP server at 192.168.5.11, blocking active FTP data transfers from VPN users.

AAdd a permit statement to allow traffic from 192.168.5.0/24 to the VPN networkCorrect

In active FTP, after the client opens the control channel to server port 21, the server initiates the data connection from its port 20 back to the client. The existing ACL permits only 192.168.5.1/32 to reach the VPN network (192.168.1.0/24), so data channel packets sourced from 192.168.5.11 are dropped by the implicit deny-any rule. Adding a permit for the full 192.168.5.0/24 subnet to the VPN network allows the FTP server to complete the active mode data channel handshake.

BAdd a permit statement to allow traffic to 192.168.5.1 from the VPN network

The existing ACL already contains a permit entry for 192.168.5.1/32 to reach the VPN network; adding a duplicate permit for that same IP resolves nothing and does not address the missing rule for the FTP server at 192.168.5.11.

CIPS is blocking traffic and needs to be reconfigured

No IPS device is referenced anywhere in the provided network configuration, so IPS misconfiguration is not a supported conclusion from the given evidence.

DConfigure the traffic shaper to limit DMZ traffic

Limiting DMZ bandwidth with the traffic shaper would reduce performance but would not restore connectivity - the issue is a missing ACL permit, not congestion.

EIncrease bandwidth limit on the VPN network

VPN users can already successfully reach the datacenter (192.168.2.0/24), proving that available VPN bandwidth is sufficient and that bandwidth is not the cause of the FTP access failure.

Concept tested: Active FTP data channel direction and ACL return traffic rules

Source: https://www.rfc-editor.org/rfc/rfc959

Topics

#VPN access#active FTP#router ACL#network troubleshooting

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice