Module 10: Zone Based Policy Firewalls Flashcards

1
Q

What are the benefits of a ZBF?

A

It is not dependent on ACLs
It blocks unless told to allow
Policies can be applied to uni directional traffic between zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the 1st design step for a ZBF?

A

Determine the zones (E.g.: “INSIDE”, “OUTSIDE”, “DMZ”).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the 2nd design step for a ZBF?

A

Establish policies between zones (E.g. TCP, UDP, sessions, echo)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the 3rd design step for ZBF?

A

Design the physical infrastructure (availability, redundant devices, etc.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the 4th design step for ZBF?

A

Identify subsets within zones and merge traffic requirements (beyond scope).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a redundant firewall?

A

A backup in case the main one fails

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a self zone?

A

The zone the router and its interfaces are in

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the “inspect” ZBF action do?

A

lets the traffic through and then back

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the “drop” ZBF action do?

A

the same as DENY

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the “Pass” ZBF action do?

A

the same as PERMIT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What happens if no policy is configured between zones?

A

all traffic is then blocked

How well did you know this?
1
Not at all
2
3
4
5
Perfectly