Juniper
JN0-696 · Question #2
Click the Exhibit button. Referring to the exhibit, PC-1 is unable to ping Server-1. Traffic from PC- 1 to Server-1 arrives on interface fe-0/0/3 but return traffic from Server-1 to PC-1 should be…
The correct answer is C. Move both interface fe-0/0/2 and fe-0/0/3 to the same security zone. See the full explanation below for the reasoning.
Question
Click the Exhibit button. Referring to the exhibit, PC-1 is unable to ping Server-1. Traffic from PC- 1 to Server-1 arrives on interface fe-0/0/3 but return traffic from Server-1 to PC-1 should be sent out from interface fe- 0/0/2. What would you change on SRX-1 to resolve this problem?
Options
- AConfigure a security policy to allow traffic from the DMZ zone to the untrust-1 zone.
- BConfigure a security policy to allow traffic from the DMZ zone to the untrust-2 zone.
- CMove both interface fe-0/0/2 and fe-0/0/3 to the same security zone.
- DDisable TCP SYN check and TCP sequence check.
How the community answered
(27 responses)- A11% (3)
- B4% (1)
- C81% (22)
- D4% (1)
Community Discussion
No community discussion yet for this question.