JN0-336 · Question #71
Click the Exhibit button. You are validating the configuration template for device access. The commands in the exhibit have been entered to secure IP access to an SRX Series device. Referring to the…
The correct answer is B. The loopback interface blocks invalid traffic on its entry into the device. D. The device manager can access the device from 10.253.1.2. The commands in the exhibit show how to configure a firewall filter on the loopback interface (lo0) of an SRX Series device. The loopback interface is a gateway for all the control traffic that enters the Routing Engine of the device. The firewall filter can be used to monitor…
Question
Click the Exhibit button. You are validating the configuration template for device access. The commands in the exhibit have been entered to secure IP access to an SRX Series device. Referring to the exhibit, which two statements are true? (Choose two.)
Options
- AThe device manager can access the device from 192.168.11.248.
- BThe loopback interface blocks invalid traffic on its entry into the device.
- CThe loopback interface blocks invalid traffic on its exit from the device.
- DThe device manager can access the device from 10.253.1.2.
How the community answered
(20 responses)- A25% (5)
- B60% (12)
- C15% (3)
Explanation
The commands in the exhibit show how to configure a firewall filter on the loopback interface (lo0) of an SRX Series device. The loopback interface is a gateway for all the control traffic that enters the Routing Engine of the device. The firewall filter can be used to monitor and protect this control traffic from various attacks. Two statements that are true based on the exhibit are: The loopback interface blocks invalid traffic on its entry into the device: The firewall filter applied on lo0 has a term that matches any packet with an invalid source address (such as 0.0.0.0/8 or 127.0.0.0/8) and discards it. This prevents spoofing or DoS attacks using invalid source addresses. The device manager can access the device from 10.253.1.2: The firewall filter applied on lo0 has a term that matches any packet with a source address of 10.253.1.2 and accepts it. This allows the device manager to access the device from this IP address using protocols such as SSH, Telnet, HTTP, or HTTPS. are applied on the loopback interfaces in virtual routers
Topics
Community Discussion
No community discussion yet for this question.