PrepAway - Latest Free Exam Questions & Answers

Which kind of table will be used by most firewalls today to keep track of the connections through the firewall

Which kind of table will be used by most firewalls today to keep track of the connections through the firewall?

PrepAway - Latest Free Exam Questions & Answers

A.
queuing

B.
netflow

C.
dynamic ACL

D.
reflexive ACL

E.
state

Explanation:
The “State” table keeps track of all connection information for traffic flows through the
firewall. The state table holds info from the headers, including source/destination IP’s
(layer 3) and port information (layer 4). It particularly takes note of SYNs , RSTs , ACKs
and FINs , and other control codes.
Incorrect:
A: No queuing table exists.
B: The Netflow table is very similar to a State Table, in that it keeps track of IP flows as
they are received by a cisco router or switch. It is used by routers and switches, though,
not by firewalls.
C: Dynamic ACL’s are stored in a router’s config , not in a table.
D: Reflexive ACL’s are inherent in Cisco firewalls, and allow return traffic from an
established flow to return through a firewall that would otherwise block such traffic. The
traffic is run against the information in the State table to see if it is return traffic… if it
exists, a reflexive acl is created. They are not stored in a table.


Leave a Reply