Chapter Review Answers

  1. Answer: C. The default operation is secure context.

  2. Answer: D. Policy is always needed to permit traffic between zones.

  3. Answer: B. The minimal security stanza is assigning all interfaces to a single zone and creating a policy that allows traffic from that zone to that zone.

  4. Answer: D. The L3 services are no longer needed and have no interface support.

  5. Answer: A. The use of 172.16.1.0/24 addressing indicates that no NAT has been performed.

  6. Answer: C, D. ASIC-based platforms such as the M7i and MX240 do not support security services. The J-series and SRX platforms provide this support.

Get Junos Enterprise Routing, 2nd Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.