1-2-3 Flashcards
In Cisco Secure Firewall, which deployment mode does NOT assign IP addresses to its interfaces?
Transparent mode.
Why would you choose Cisco Secure Firewall in transparent mode for deployment?
To add security without changing existing network IP addressing or topology.
Name two advanced features unsupported in Cisco Secure Firewall’s Transparent mode.
VPN termination and dynamic routing protocols.
What is the main operational difference between Transparent and Routed firewall modes?
Transparent mode operates at Layer 2 without changing network topology, whereas Routed mode operates at Layer 3 as a routed network hop.
What does the “fail-to-wire” feature on Inline interfaces accomplish?
It allows traffic to continue passing through if the firewall loses power or experiences a software failure, ensuring business continuity.
What advantage does firewall clustering have over failover pairs?
Clustering supports active-active configurations, enhancing both network availability and throughput simultaneously.
Why might you deploy Cisco Secure Firewall in Transparent mode instead of Routed mode in an existing network?
To add security without altering the existing IP addressing or network structure.
If an organization prioritizes uninterrupted network operation over immediate blocking capabilities during initial IPS testing, which interface mode should they select?
Inline Tap mode, as it detects malicious traffic without blocking it.