nerdexam
Juniper

JN0-637 · Question #102

You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces…

The correct answer is A. You are unable to apply stateful security features to traffic that is switched between the two C. The interfaces will not forward traffic by default. When Ethernet interfaces are configured as Layer 2 and added to the same VLAN without being assigned to a security zone, they will not forward traffic by default. Additionally, because they are operating in a pure Layer 2 switching mode, they lack the capability to enforce…

Advanced Junos OS Security Platform

Question

You configure two Ethernet interfaces on your SRX Series device as Layer 2 interfaces and add them to the same VLAN. The SRX is using the default L2-learning setting. You do not add the interfaces to a security zone. Which two statements are true in this scenario? (Choose two.)

Options

  • AYou are unable to apply stateful security features to traffic that is switched between the two
  • BYou are able to apply stateful security features to traffic that enters and exits the VLAN.
  • CThe interfaces will not forward traffic by default.
  • DYou cannot add Layer 2 interfaces to a security zone.

How the community answered

(42 responses)
  • A
    81% (34)
  • B
    12% (5)
  • D
    7% (3)

Explanation

When Ethernet interfaces are configured as Layer 2 and added to the same VLAN without being assigned to a security zone, they will not forward traffic by default. Additionally, because they are operating in a pure Layer 2 switching mode, they lack the capability to enforce stateful security When two interfaces are configured as Layer 2 interfaces and belong to the same VLAN but are not assigned to any security zone, traffic switched between them is handled purely at Layer 2. Stateful security features, such as firewall policies, are applied at Layer 3, so traffic between these interfaces will not undergo any stateful inspection or firewalling by default. In Junos, Layer 2 interfaces must be added to a security zone to allow traffic forwarding. Since the interfaces in this scenario are not part of a security zone, they will not forward traffic by default until assigned to a zone. This is a security measure to prevent unintended forwarding of traffic. Juniper Security Reference:

Topics

#Layer 2 interfaces#VLAN#L2-learning#security zones

Community Discussion

No community discussion yet for this question.

Full JN0-637 Practice