ExamGecko
Question list
Search
Search

Related questions











Question 78 - HPE7-A01 discussion

Report
Export

A customer wants to provide wired security as close to the source as possible The wired security must meet the following requirements:

-allow ping from the IT management VLAN to the user VLAN

-deny ping sourcing from the user VLAN to the IT management VLAN

The customer is using Aruba CX 6300s

What is the correct way to implement these requirements?

A.
Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN
Answers
A.
Apply an outbound ACL on the user VLAN allowing temp echo-reply traffic toward the IT management VLAN
B.
Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN
Answers
B.
Apply an inbound ACL on the user VLAN allowing icmp echo-reply traffic toward the IT management VLAN
C.
Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN
Answers
C.
Apply an inbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN
D.
Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN
Answers
D.
Apply an outbound ACL on the user VLAN denying icmp echo traffic toward the IT management VLAN
Suggested answer: C

Explanation:

An inbound ACL is applied to traffic entering a port or VLAN.An outbound ACL is applied to traffic leaving a port or VLAN4. To deny ping sourcing from the user VLAN to the IT management VLAN, an inbound ACL on the user VLAN should be used to filter icmp echo traffic toward the IT management VLAN.Icmp echo-reply traffic is not needed to be allowed because it is already permitted by default5.

Reference:4https://techhub.hpe.com/eginfolib/Aruba/OS-CX_10.04/5200-6692/GUID-9B8F6E8F-9C7A-4F0D-AE7B-9D8E6C5B6A7F.html5https://techhub.hpe.com/eginfolib/Aruba/OS-CX_10.04/5200-6692/GUID-0C3A9D0F-6E5B-4E1A-AF3C-8D8B2F9C1A7B.html

asked 16/09/2024
Piotr Szwajkowski
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first