Juniper
JN0-636 · Question #63
Click the Exhibit button. You are implementing a new branch site and want to ensure Internet traffic is sent directly to your ISP and other traffic is sent to your company headquarters. You have…
The correct answer is A. The session utilizes one routing instance C. The ge-0/0/5 and ge-0/0/1 interfaces can reside in different security zones. See the full explanation below for the reasoning.
Question
Click the Exhibit button.
You are implementing a new branch site and want to ensure Internet traffic is sent directly to your ISP and other traffic is sent to your company headquarters. You have configured filter-based forwarding to accomplish this objective. You verify proper functionality using the outputs shown in the exhibit.
Exhibit:
user@srx> telnet 172.20.202.10
Connected to 172.20.202.10.
Escape character is '^]'.
remote device (ttyp1)
login:
user@srx> show security flow session application telnet
Session ID: 50746, Policy name: FBF_internet/11, Timeout: 1722, Valid
In: 172.20.201.10/63630 --> 172.20.202.10/23;tcp, Conn Tag: 0x0, If: ge-0/0/5.0,
Pkts: 24, Bytes: 1624
Out: 172.20.202.10/23 --> 172.20.201.10/55530;tcp, Conn Tag: 0x0, If:
ge-0/0/1.0, Pkts: 22, Bytes: 1418,
Total sessions: 1
Which two statements are true in this scenario? (Choose two.)
Options
- AThe session utilizes one routing instance
- BThe ge-0/0/5 and ge-0/0/1 interfaces must reside in a single security zone
- CThe ge-0/0/5 and ge-0/0/1 interfaces can reside in different security zones
- DThe session utilizes two routing instances
How the community answered
(30 responses)- A80% (24)
- B7% (2)
- D13% (4)
Community Discussion
No community discussion yet for this question.