MX devices can be configured in a high-availability pair (warm spare) using one of two MX addressing options (Security & SD-WAN > Configure > Addressing & VLANs):
Passthrough or VPN Concentrator mode
Routed mode
BE
It is A and E since we cannot have VLANs configured in passthrough VPN concentrator mode. In fact, I just checked right now that the Site to Site VPN is through the VLANs.
A & B
In Passthrough Mode, since the Meraki device is not actively performing routing functions or managing network traffic in the same way, High Availability is NOT SUPPORTED.
AB
You can enable intrusion prevention by setting the Mode drop-down to Prevention under Security & SD-WAN > Configure > Threat protection > Intrusion detection and prevention. Traffic will be automatically blocked by best effort if it is detected as malicious based on the detection ruleset specified above.
Protected Network section is used to controls the IP addresses or subnets of the systems protectied. Entries should be separated by commas or blank space(s). This will narrow down the subnets protected, it will protect only the subnets listed.
Note: The Protected Network section is only available for Security Appliances in Passthrough mode.
https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection#:~:text=The%20MX's%20Intrusion%20Detection%20and,to%20ensure%20networks%20are%20safeguarded.
Guys, I have this exact scenario in production right now and the answer is AE. We have two MX250s in passthrough mode for Intrusion PREVENTION and they are setup in HA. While they can technically do site-to-site VPN, but if they did, they would be considered CONCENTRATORS and not as pass-thru devices as per all Meraki official documentation as well as the description in the dashboard itself - thus AE is the most correct answer.
When in passthrough mode, the MX is best used for in-line:
Layer 3/7 firewall rules, traffic shaping, and analysis
Network asset discovery and reporting
Intrusion detection
Security and content filtering
Client and site-to-site VPN
This section is not available anymore. Please use the main Exam Page.500-220 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
zaazanuna
3 weeks, 5 days agoPenza
1 month, 2 weeks ago3ebcffa
2 months, 1 week agoilcarletto
4 months agoyottabyte_
5 months agosattori
6 months, 2 weeks agoMPIAZZAL
8 months agoGilgamesh_SHA
10 months, 2 weeks ago5448108
10 months, 3 weeks agojzzmth
11 months, 1 week agoAnyParka0B
1 year, 1 month agoXalaGyan
1 year, 4 months agonyashac
1 year, 5 months agornunes1110
1 year, 6 months agofredbarron010
1 year, 7 months agornunes1110
1 year, 7 months agoCaptainPirate
1 year, 10 months ago