ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 15 - JN0-636 discussion

Report
Export

Exhibit

Which two statements are correct about the output shown in the exhibit? (Choose two.)

A.
The packet is processed as host inbound traffic.
Answers
A.
The packet is processed as host inbound traffic.
B.
The packet matches the default security policy.
Answers
B.
The packet matches the default security policy.
C.
The packet matches a configured security policy.
Answers
C.
The packet matches a configured security policy.
D.
The packet is processed in the first path packet flow.
Answers
D.
The packet is processed in the first path packet flow.
Suggested answer: A, D

Explanation:

The packet is processed as host inbound traffic because the traceoptions output shows that the destination IP address 10.10.10.1 belongs to the SRX device itself, which is configured with the ge-0/0/1.0 interface. The traceoptions output also shows the flag flow_host_inbound, which indicates that the packet is destined to the device.

The packet matches the default security policy because the traceoptions output shows that the policy name is default-deny, which is the implicit system-default security policy that denies all packets. The traceoptions output also shows the flag flow_policy_deny, which indicates that the packet is denied by the policy.

Reference:

traceoptions (Security NAT) | Junos OS | Juniper Networks

[SRX] How to interpret Flow TraceOptions output for NAT troubleshooting Default Security Policies | Junos OS | Juniper Networks

asked 18/09/2024
Rakesh Sharma
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first