Q35Layer 3 Technologies
Refer to the exhibit. A network administrator configured an IPv6 access list to permit only TCP return traffic, but it is not operating as intended. Which changes fix this issue?
← → navigate · a answer
Discussion · 4
13
TCP hosts create a connection-oriented session with each other using a “three-way handshake” process.
As far as I know, the TCP return frame is the last frame involved in the three-way handshake (the ACK frame). Then the session between the two hosts is established.
So:
permit tcp any any established (let the TCP return frame in, from any host)
deny ipv6 any any log (deny any other IPv6 traffic from any host)
Since the TCP return frame has to be allowed IN, the ACL must be applied IN.
Answer A is correct.
2
A and B could both be correct. It is not clear whether it is about traffic to or from the router. I assumed the TCP session toward the router and picked B. Is there any indication of the session direction that I missed?
1
great explanation!
1
out keyword does not help us. This wont affect traffic coming to router. That leaves A or C. C is not the correct answer: TCP permit any any SYN" refers to a firewall rule that allows any TCP connection with the SYN flag set from any source to any destination.
TCP: Refers to the Transmission Control Protocol.
permit: Indicates that the traffic matching the rule is allowed.
any any: Applies to any source and destination IP addresses.
SYN: Stands for the Synchronize flag, which is set in the first step of the TCP three-way handshake, initiating a TCP connection. If C was permit tcp any any syn and permit tcp any any ack this may work, but this also allows new tcp connections