PCNSE · Question #653
A Security policy rule is configured with a Vulnerability Protection Profile and an action of "Deny". Which action will this configuration cause on the matched traffic?
The correct answer is A. It will cause the firewall to deny the matched sessions. Any configured Security Profiles have no. If you want to block traffic from zone A to zone B and you have configured the security rule to block this traffic, lets say the first packet comes from zone A, we do a route lookup and find the destination zone to be zone B. You will then do a policy lookup and see that there is
Question
A Security policy rule is configured with a Vulnerability Protection Profile and an action of "Deny". Which action will this configuration cause on the matched traffic?
Options
- AIt will cause the firewall to deny the matched sessions. Any configured Security Profiles have no
- BThe configuration will allow the matched session unless a vulnerability signature is detected. The
- CIt will cause the firewall to skip this Security policy rule. A warning will be displayed during a
- DThe Profile Settings section will be grayed out when the Action is set to "Deny".
How the community answered
(66 responses)- A86% (57)
- B3% (2)
- C3% (2)
- D8% (5)
Explanation
If you want to block traffic from zone A to zone B and you have configured the security rule to block this traffic, lets say the first packet comes from zone A, we do a route lookup and find the destination zone to be zone B. You will then do a policy lookup and see that there is a policy match. But since the action is set to "deny", the packet is dropped immediately. Firewall will only inspect the traffic if the policy it matched has action set to "allow".
Topics
Community Discussion
No community discussion yet for this question.