Chapter 4


What is the difference between stateful and stateless ACLs?


Stateful ACLs track transport state information, such as IP addresses, TCP/UDP ports, TCP sequence numbers, and TCP flags. Stateful ACLs do not track any transport information.


How do stateful ACLs track transport state information?


Basic ACLs track transport state simply by checking to see if the ACK or RST TCP flags are set in the TCP header. IP session filters create temporary ACL entries for return traffic. CBAC and PIX firewalls store transport state information for each connection in a state table. The table includes IP addresses, TCP/UDP ports, TCP sequence numbers, and TCP flags.


How can you approximate UDP connections?


You can approximate UDP connections by tracking packets with the same source and destination IP addresses and ports that transit the firewall over the same time frame.


How can you achieve supervisor redundancy?


Supervisor redundancy is achieved by installing two supervisors in a single chassis, or by using two chassis with a single supervisor installed in each.


How can you achieve switch fabric redundancy?


For active backplanes, two chassis are required for redundancy. For passive backplanes (that is, SFMs or integrated switch fabrics), either two modules in a single chassis or two chassis with a single module each are required for redundancy.


What is one benefit of sandwiching public servers between two firewalls?


Both single and dual firewall configurations secure internal resources from the public resources. However, server sandwiching enables firewalls of different vendors to secure internal resources.


What content networking solutions do remote branch users benefit from?


Remote office users benefit from content edge delivery, distribution, and routing in order to place content closer to the client.

Content Networking Fundamentals
ISBN: 1587052407
EAN: 2147483647
Year: N/A
Pages: 178

