Chapter 8

1: How does ASA keep track of UDP connections?
A1: Answer: It uses timers.
2: What does ASA do to the TCP sequence number of packets passing through it?
A2: Answer: It randomizes the TCP sequence number and keeps track of the change in the new and old sequence numbers.
3: What does the PIX's mail guard feature do?
A3: Answer: It allows only the seven well-known SMTP commands to go through and returns an OK while discarding any other commands.
4: What is the purpose of the ARP test in PIX's failover mechanism?
A4: Answer: The ARP test consists of reading the unit's ARP cache for the 10 most recently acquired entries. The unit sends ARP requests one at a time to these machines, attempting to stimulate network traffic. After each request, the ...

Get Network Security Principles and Practices now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.