JN0-635 · Question #11
Your network includes SRX Series devices at the headquarters location. The SRX Series devices at this location are part of a high available chassis cluster and are configured for IPS. There has been…
The correct answer is B. Cached SSL session ID information for existing sessions is not synchronized between nodes. C. The IP action table is not synchronized between the chassis cluster nodes. By default, IDP ignores failover sessions in an SRX Series chassis cluster deployment. The drop- on-failover option changes this behavior and automatically drops sessions that are in the process of being inspected on the primary node when a failover to the secondary node…
Question
Your network includes SRX Series devices at the headquarters location. The SRX Series devices at this location are part of a high available chassis cluster and are configured for IPS. There has been a node failover. In this scenario, which two statements are true? (Choose two.)
Options
- AThe IP action table is synchronized between the chassis cluster nodes.
- BCached SSL session ID information for existing sessions is not synchronized between nodes.
- CThe IP action table is not synchronized between the chassis cluster nodes.
- DCached SSL session ID information for existing session is synchronized between nodes.
How the community answered
(71 responses)- A15% (11)
- B79% (56)
- D6% (4)
Explanation
By default, IDP ignores failover sessions in an SRX Series chassis cluster deployment. The drop- on-failover option changes this behavior and automatically drops sessions that are in the process of being inspected on the primary node when a failover to the secondary node occurs. IPS with Chassis Clustering Limitations IPS is supported in both active/passive and active/active chassis cluster modes on SRX Series devices with the following limitations: 1. No inspection is performed on sessions that fail over or fail back. Only new sessions after a failover are inspected by IPS, and older sessions become firewall sessions. 2. The IP action table is not synchronized across nodes. If an IP action is taken for a session, and the source IP, destination IP or both is added to the IP action table, this information is not synchronized to the secondary node. Therefore, the sessions from the source IP, destination IP or both will be forwarded until a new attack is detected. 3. The SSL session ID cache is not synchronized across nodes. If an SSL session reuses a session ID and it happens to be processed on a node other than the one on which the session ID is cached, the SSL session cannot be decrypted and will be bypassed for IPS inspection.
Topics
Community Discussion
No community discussion yet for this question.