Refer to the Exhibit.
— Exhibit –
— Exhibit —
TCP traffic sourced from Host A destined for Host B is being redirected using filter-based
forwarding to use the Red network. However, return traffic from Host B destined for Host A is
using the Blue network and getting dropped by the SRX device.
Which action will resolve the issue?
A.
Enable asyncronous-routing under the Blue zone.
B.
Configure ge-0/0/1 to belong to the Red zone.
C.
Disable RPF checking.
D.
Disable TCP sequence checking.
Explanation:
Reference:https://kb.juniper.net/InfoCenter/index?page=content&id=KB21046
Answer is B . 🙂
AJSEC book part 1 chapter 4 page 41 .
“To avoid this scenario , we recommend that both egress interfaces reside in the same security zone”
answer is B. this is Filter based forwarding so egress interface should be part of same zone .