exam questions

Exam 350-801 All Questions

View all questions & answers for the 350-801 exam

Exam 350-801 topic 1 question 66 discussion

Actual exam question from Cisco's 350-801
Question #: 66
Topic #: 1
[All 350-801 Questions]

Which action is required for a firewall configuration on a Mobile and Remote Access through Cisco Expressway deployment?

  • A. The external firewall must allow these inbound connections to Expressway: SIP: TCP 5061: HTTPS: TCP 8443; XMPP: TCP 5222; Media: UDP 36002 to 59999.
  • B. The internal firewall must allow these inbound and outbound connections between Expressway-׀¡ and Expressway-E: SIP: HTTPS (tunneled over SSH between ׀¡ and E): TCP 2222: TCP 7001; Traversal Media: UDP 2776 to 2777 (or 36000 to 36011 for large VM/appliance); XMPP: TCP 7400.
  • C. Do not use a shared address for Expressway-E and Expressway-׀¡, as the firewall cannot distinguish between them. If static NAT for IP addressing on Expressway-E is used, ensure that any NAT operation on Expressway-׀¡ does not resolve the same traffic IP address. Shared NAT is not supported.
  • D. The traversal zone on Expressway-׀¡ points to Expressway-E through the peer address field on the traversal zone, which specifies the Expressway-E server address. For dual NIC deployments, set the Expressway-E address using an FQDN that resolves the IP address of the internal interface.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
ciscogeek
Highly Voted 3 years, 1 month ago
Selected Answer: A
https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X14-0-2/mra/exwy_b_mra-deployment-guide-x1402.pdf
upvoted 5 times
H31d1
2 years, 8 months ago
P. 14 says A C and D are correct?
upvoted 2 times
G0y0
3 months, 4 weeks ago
C. and D. are correct, however, they apply as for B2B deployments as for MRA deployment. A. and B. are focused to RMA what is the focus of the answer, and finally just remain A.
upvoted 1 times
G0y0
3 months, 4 weeks ago
In fact, all of the four are correct, however, B makes the mistake of saying that the inbound firewall should allow inbound and outbound connections, which is a mistake. The internal firewall should only have outbound rules, from Exp-C to Exp-E.
upvoted 1 times
...
...
way2certs
2 years, 7 months ago
Indeed. As the question asks about firewall configuration , just A seems relevant out of the three.
upvoted 2 times
...
...
...
G0y0
Most Recent 3 months, 4 weeks ago
Selected Answer: A
Well, let us see: Actually, all of the four answers are correct, they just differ in the context. C. and D. are correct, even though they apply both as for B2B as for MRA, as for a Traversal Client/Server Zone as for a Unified Communications Traversal Zone. Remember the question is asking just for MRA. B. is partially correct, even the port usage is correct, the truth is that no inbound ports are required to be opened on the internal firewall. The internal firewall must allow only outbound connections from the Expressway-C to the Expressway-E. A. is the most appropriate. The external firewall must allow inbound connections to the Expressway-E: SIP (TCP 5061); HTTPS (TCP 8443); XMPP (TCP 5222); Media (UDP 36002 to 59999)
upvoted 1 times
G0y0
3 months, 4 weeks ago
Reference: Cisco Expressway IP Port Usage Configuration Guide (X14.0); CCNP Collaboration Cloud and Edge Solutions CLCEI 300-820 Official Cert Guide.
upvoted 1 times
...
...
b3532e4
10 months, 1 week ago
A. The external firewall and B. The internal firewall is correct but in this Q not mention it Which firewall? My opinion C is Correct
upvoted 1 times
...
AgshinA
1 year, 3 months ago
Selected Answer: A
Guide says exactly the same: The external firewall must allow the following inbound connections to Expressway: SIP: TCP 5061; HTTPS: TCP 8443; XMPP: TCP 5222; Media: UDP 36002 to 59999. https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/expressway/config_guide/X14-2/mra/exwy_b_mra-deployment-guide-x142/exwy_m_requirements-for-mra.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...