nerdexam
Juniper

JN0-522 · Question #133

You have created your tunnel interface in the untrust zone. Traffic from the trust zone is able to enter the tunnel and pass to the destination. However traffic from a different interface in the…

The correct answer is B. A policy is needed since intra-zone blocking is on by default in the untrust zone. Juniper JN0-522 Exam

Troubleshooting

Question

You have created your tunnel interface in the untrust zone. Traffic from the trust zone is able to enter the tunnel and pass to the destination. However traffic from a different interface in the untrust zone is not able to pass traffic through the tunnel. You are using a single virtual router. What is causing this problem?

Options

  • ATwo virtual routers need to be configured.
  • BA policy is needed since intra-zone blocking is on by default in the untrust zone.
  • CThe tunnel is configured with a proxy id that does not include the address from the untrust interface.
  • DThe routing tables are not correctly configured to allow the traffic from the untrust source to bedelivered

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    81% (35)
  • C
    9% (4)
  • D
    2% (1)

Explanation

Juniper JN0-522 Exam

Topics

#intra-zone blocking#untrust zone#tunnel interface#zone policy

Community Discussion

No community discussion yet for this question.

Full JN0-522 Practice