ExamGecko
Question list
Search
Search

Question 529 - 156-315.81 discussion

Report
Export

An established connection is going to www.google.com. The Application Control Blade Is inspecting the traffic. If SecureXL and CoreXL are both enabled, which path is handling the traffic?

A.
Slow Path
Answers
A.
Slow Path
B.
Fast Path
Answers
B.
Fast Path
C.
Medium Path
Answers
C.
Medium Path
D.
Accelerated Path
Answers
D.
Accelerated Path
Suggested answer: D

Explanation:

The traffic is handled by the Accelerated Path.According to the R81.x Security Gateway Architecture (Logical Packet Flow)1, the Accelerated Path is the fastest path for processing packets, as it bypasses most of the inspection and uses SecureXL to accelerate the traffic.The Accelerated Path is used for connections that are established, compliant with the security policy, and do not require any content inspection or NAT1.

The Application Control blade inspects the traffic based on the application identity, which is determined by the Application Control Software Blade in the Medium Path1.However, once the application identity is established, the connection can be offloaded to SecureXL and handled by the Accelerated Path2.This way, the Application Control blade can improve performance and reduce CPU consumption2.

The other paths are not used for this traffic because:

The Slow Path is used for packets that are not compliant with the security policy, require stateful inspection or NAT, or are not supported by SecureXL1.This path involves the most inspection and processing, and is therefore the slowest3.

The Fast Path is used for packets that are trusted and do not require any inspection or NAT.This path bypasses both SecureXL and the Firewall kernel, and uses a kernel module called simfast to forward the packets directly to the network interface driver4.This path is not enabled by default, and requires manual configuration of rules to define which traffic can use it4.

The Medium Path is used for packets that require content inspection, such as IPS, Anti-Virus, Anti-Bot, URL Filtering, or Application Control1.This path uses SecureXL to accelerate some parts of the inspection, but still involves some processing by the Firewall kernel3.This path is only used for the first few packets of a connection until the application identity is established, and then the connection can be offloaded to the Accelerated Path2.

asked 16/09/2024
Emma Buchanan
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first