nerdexam
Juniper

JN0-632 · Question #12

Your company has installed a new transparent proxy server that it wants all employee traffic to traverse before taking the default route to the Internet. The proxy server is within two DMZ zones…

The correct answer is B. Configure two separate routing instances: one instance for the employee zone to the ingress proxy. See the full explanation below for the reasoning.

Question

Your company has installed a new transparent proxy server that it wants all employee traffic to traverse before taking the default route to the Internet. The proxy server is within two DMZ zones from the SRX Series device, which means your SRX device must now have two default routes:

one to the proxy DMZ and one to the Internet from the proxy DMZ. What can you do to get the traffic to flow to the transparent proxy DMZ, and then from the proxy DMZ to the Internet, regardless of the destination or port?

Options

  • AConfigure two static default floating routes: one from the employee zone to the ingress proxy DMZ
  • BConfigure two separate routing instances: one instance for the employee zone to the ingress proxy
  • CConfigure security policies that will route all traffic to the ingress proxy DMZ then traffic will follow
  • DConfigure a rib-group to handle the two default routes between the ingress and egress zones of the

How the community answered

(35 responses)
  • A
    9% (3)
  • B
    74% (26)
  • C
    14% (5)
  • D
    3% (1)

Community Discussion

No community discussion yet for this question.

Full JN0-632 Practice