<< Prev Question Next Question >>

Question 26/36

-- Exhibit --
user@host> show configuration security policies from-zone engineering to-zone hr policy new-policy { match { source-address any;
destination-address server1;
application hr-data-feed;
}
then {
permit;
}
}
policy old-policy {
match {
source-address pc1;
destination-address server1;
application any;
}
then {
deny;
log {
session-init;
}
}
}
user@host> show configuration security policies global
user@host> show configuration security address-book | match server1 | display set set security address-book book2 address server1 172.19.55.20/32 set security address-book book3 address server1 172.20.11.18/32 user@host> show configuration security address-book | match pc1 | display set set security address-book book1 address pc1 172.18.21.213/32 user@host> show configuration applications application hr-data-feed {
protocol tcp;
destination-port 38888;
}
user@host> run show log flow-traceoptions | no-more
Jun 13 15:54:09 host clear-log[2503]: logfile cleared
Jun 13 15:54:10 15:54:10.611915:CID-0:RT:172.18.21.213/38362->172.19.55.20/38888;17> matched filter filter1:
Jun 13 15:54:10 15:54:10.611915:CID-0:RT:packet [40] ipid = 38364, @423e421c Jun 13 15:54:10 15:54:10.611915:CID-0:RT:---- flow_process_pkt: (thd 3): flow_ctxt type 15, common flag
0x0, mbuf 0x423e4000, rtbl_idx = 0
Jun 13 15:54:10 15:54:10.611915:CID-0:RT: flow process pak fast ifl 70 in_ifp ge-0/0/8.0 Jun 13 15:54:10 15:54:10.611915:CID-0:RT: find flow: table 0x49175b08, hash 9077(0xffff), sa
172.18.21.213, da 172.19.55.20, sp 38362, dp 38888, proto 17, tok 10
Jun 13 15:54:10 15:54:10.611915:CID-0:RT: flow_first_create_session
Jun 13 15:54:10 15:54:10.611915:CID-0:RT: flow_first_in_dst_nat: in 0/8.0>, out A> dst_adr
172.19.55.20, sp 38362, dp 38888
Jun 13 15:54:10 15:54:10.611915:CID-0:RT: chose interface ge-0/0/8.0 as incoming nat if.
Jun 13 15:54:10 15:54:10.611915:CID-0:RT:flow_first_rule_dst_xlate: DST no-xlate: 0.0.0.0(0) to
172.19.55.20(38888)
Jun 13 15:54:10 15:54:10.611915:CID-0:RT:flow_first_routing: vr_id 0, call flow_route_lookup(): src_ip
172.18.21.213, x_dst_ip 172.19.55.20, in ifp ge-0/0/8.0, out ifp N/A sp 38362, dp 38888, ip_proto 17, tos 0 Jun 13 15:54:10 15:54:10.611915:CID-0:RT:Doing DESTINATION addr route-lookup Jun 13 15:54:10 15:54:10.611915:CID-0:RT: routed (x_dst_ip 172.19.55.20) from engineering (ge-0/0/8.0 in 0) to ge-0/0/10.0, Next-hop: 172.19.55.20 Jun 13 15:54:10 15:54:10.611915:CID-0:RT:flow_first_policy_search: policy search from zone engineering-> zone hr (0x0,0x95da97e8,0x97e8) Jun 13 15:54:10 15:54:10.611915:CID-0:RT: app 0, timeout 60s, curr ageout 60s Jun 13 15:54:10 15:54:10.611915:CID-0:RT: Error : get sess plugin info 0x4c390388 Jun 13 15:54:10 15:54:10.611915:CID-0:RT: Error : get sess plugin info 0x4c390388 Jun 13 15:54:10 15:54:10.612416:CID-0:RT: packet dropped, denied by policy Jun 13 15:54:10 15:54:10.612416:CID-0:RT: denied by policy old-policy(6), dropping pkt Jun 13 15:54:10 15:54:10.612416:CID-0:RT: packet dropped, policy deny.
Jun 13 15:54:10 15:54:10.612416:CID-0:RT: flow didn't create session, code=-1.
Jun 13 15:54:10 15:54:10.612416:CID-0:RT: ----- flow_process_pkt rc 0x7 (fp rc -1)
-- Exhibit --
Click the Exhibit button.
A user added the new-policy policy to permit traffic. However, they report that the traffic is still not permitted by the device.
Using the information in the exhibit, why is the device denying the traffic?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (36q)
Question 1: -- Exhibit -- Apr 27 19:11:09 company-fw init: low_mem_signa...
Question 2: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 3: -- Exhibit -- user@host&gt; request services application-ide...
Question 4: -- Exhibit -- [edit security utm] user@host# show custom-obj...
Question 5: LAN 1 and LAN 2 are experiencing network communication probl...
Question 6: Click the Exhibit button. (Exhibit) A customer wants to crea...
Question 7: -- Exhibit -- user@host&gt; show security flow session ... S...
Question 8: -- Exhibit -- user@host&gt; show log ibgp-trace ... Jun 12 1...
Question 9: -- Exhibit -- user@host&gt; show log ike-test ... Jun 13 10:...
Question 10: Click the Exhibit button. (Exhibit) A customer configured DH...
Question 11: -- Exhibit -- user@host&gt; show log flow.log Jun 12 20:00:4...
Question 12: -- Exhibit -- user@R1&gt; show security ike security-associa...
Question 13: Click the Exhibit button. (Exhibit) You configured a route-b...
Question 14: Click the Exhibit button. (Exhibit) You are implementing a h...
Question 15: Click the Exhibit button. (Exhibit) You recently configured ...
Question 16: You have deployed AppID on your SRX Series device. You want ...
Question 17: Click the Exhibit button. (Exhibit) You are implementing UTM...
Question 18: -- Exhibit -- user@R1&gt; show log ike-trace Jun 13 07:45:10...
Question 19: Click the Exhibit button. (Exhibit) A customer created a sec...
Question 20: -- Exhibit -- user@host&gt; show security flow session inter...
Question 21: -- Exhibit -- user@host&gt; show configuration security utm ...
Question 22: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 23: Click the Exhibit button. (Exhibit) A customer is using a de...
Question 24: -- Exhibit -- [edit] user@SRX-1# show security ike traceopti...
Question 25: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 26: -- Exhibit -- user@host&gt; show configuration security poli...
Question 27: -- Exhibit -- {primary:node0} user@host&gt; show configurati...
Question 28: Click the Exhibit button. (Exhibit) Your customer reports th...
Question 29: -- Exhibit -- {hold:node0} user@host1&gt; show chassis clust...
Question 30: While attempting to commit a configuration for a new address...
Question 31: Click the Exhibit button. (Exhibit) You are troubleshooting ...
Question 32: Click the Exhibit button. (Exhibit) A customer wants to comm...
Question 33: -- Exhibit - (Exhibit) -- Exhibit -- Click the Exhibit butto...
Question 34: -- Exhibit -- user@host&gt; show configuration ... security ...
Question 35: -- Exhibit -- user@SRX-1&gt; show configuration security ike...
Question 36: Users begin complaining that they are not able to access res...