HP
HPE6-A45 · Question #79
A company starts to have issues with too many rules in the dynamic ACLs applied to AOS-Switch ports. Administrators decide to remove some of the common rules from the dynamic ACLs and enforce them…
The correct answer is C. Traffic must be permitted by both the dynamic ACL and the VLAN ACL in order to be permitted. See the full explanation below for the reasoning.
Question
A company starts to have issues with too many rules in the dynamic ACLs applied to AOS-Switch ports. Administrators decide to remove some of the common rules from the dynamic ACLs and enforce them in an ACL applied to the users' VLAN instead. What is one rule that administrators should keep in mind to ensure that the new ACLs control traffic as they expect?
Options
- AACLs applied to VLANs will not block ICMP traffic by the dynamic ACLs that ensure the ICMP rules.
- BAdministrators should add an explicit deny at the end of the dynamic ACLs, so traffic will hit VLAN ACL.
- CTraffic must be permitted by both the dynamic ACL and the VLAN ACL in order to be permitted.
- DIf a port supports multiple clients, every dynamic ACL applied to the client filters traffic for all clients.
How the community answered
(31 responses)- A3% (1)
- B3% (1)
- C84% (26)
- D10% (3)
Community Discussion
No community discussion yet for this question.