ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 19 - JN0-636 discussion

Report
Export

Exhibit

Which two statements are correct about the output shown in the exhibit? (Choose two.)

A.
The packet is silently discarded.
Answers
A.
The packet is silently discarded.
B.
The packet is part of an existing session.
Answers
B.
The packet is part of an existing session.
C.
The packet is part of a new session.
Answers
C.
The packet is part of a new session.
D.
The packet is explicitly rejected.
Answers
D.
The packet is explicitly rejected.
Suggested answer: A, C

Explanation:

The packet is silently discarded because the traceoptions output shows that the packet is dropped with the flag flow_spu_drop, which indicates that the packet is dropped by the SPU without sending any response to the sender. The traceoptions output also shows the reason for the drop as "no session found, start first path. in_tunnel - 0, from_cp_flag - 0" which means that the packet does not match any existing session and is not part of a tunnel or a control plane traffic1.

The packet is part of a new session because the traceoptions output shows that the packet is the first packet of a TCP connection with the flag flow_tcp_syn, which indicates that the packet has the SYN flag set. The traceoptions output also shows that the packet is processed in the first path packet flow with the message "no session found, start first path" which means that the packet is initiating a new session1.

Reference:

traceoptions (Security Flow) | Junos OS | Juniper Networks

[SRX] How to interpret Flow TraceOptions output for NAT troubleshooting

asked 18/09/2024
Joseph Mwaura
29 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first