A -> because by keeping the denied sessions in the session table reduces the number of session denied events in the logs, D -> because you are keeping denied sessions in the session table, Not C -> set block-session-timer {integer} Duration in seconds for blocked sessions (1 - 300 sec (5 minutes), default = 30). range[1-300]
C is not correct as the timer is in seconds
Only A & D:
Blocking the packets of a denied session can take more CPU processing resources than passing the traffic through. The configuration is to enable denied session to be added into the session table to reduce the CPU processing.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
alex_iec
Highly Voted 5 years, 5 months agoRondo
Highly Voted 4 years, 9 months agohenzoo
Most Recent 4 years, 4 months agoramzie
4 years, 6 months agoOCZY
4 years, 6 months agoMohamed_M
4 years, 7 months agoMohammad_Rummaneh
4 years, 9 months agoEvanABS
5 years, 1 month agoZameerKhan
5 years, 2 months ago