Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco Exam 300-710 Topic 11 Question 106 Discussion

Actual exam question for Cisco's 300-710 exam
Question #: 106
Topic #: 11
[All 300-710 Questions]

An engineer is troubleshooting application failures through a FTD deployment. While using the FMC CLI. it has been determined that the traffic in question is not matching the desired policy. What should be done to correct this?

Show Suggested Answer Hide Answer
Suggested Answer: B

To configure an isolated bridge group for Integrated Routing and Bridging (IRB) mode on a Cisco Secure Firewall device, the action to take is to leave the BVI (Bridge Virtual Interface) interface name empty. This ensures that the bridge group operates in an isolated manner, where Layer 3 routing is not applied to the bridged interfaces, effectively isolating the traffic within the bridge group.

Steps:

Access the firewall's configuration interface.

Configure the bridge group interfaces.

Ensure that the BVI interface name is left empty to isolate the bridge group.

This configuration prevents Layer 3 routing for the isolated bridge group, ensuring that traffic remains contained within the bridge group.


Contribute your Thoughts:

Xenia
10 days ago
I'm not sure about that. Maybe we should also consider using the system support application-identification-debug command to get more insights.
upvoted 0 times
...
Arlette
16 days ago
B) Checking the application identification debugging could be useful, but I'm not sure if that's the best option to directly resolve the issue here.
upvoted 0 times
...
Glendora
18 days ago
A) Seems like the right approach to debug the firewall engine and modify the rule accordingly. I'm confident this is the correct answer.
upvoted 0 times
Keena
4 days ago
B) Once we know which rules the traffic is matching, we can modify the rule accordingly.
upvoted 0 times
...
Telma
6 days ago
A) I think we should use the system support firewall-engine-debug command to determine which rules the traffic is matching.
upvoted 0 times
...
...
Tashia
18 days ago
I agree with Paz. Once we know which rules the traffic is matching, we can modify the rule accordingly to correct the issue.
upvoted 0 times
...
Paz
23 days ago
I think we should use the system support firewall-engine-debug command to determine which rules the traffic is matching.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77