You have created a series of security policies permitting access to a variety of services. You now want to create a policy that blocks access to all other services for all user groups.
To enforce acatch-all blocking policyafter other specific policies, the correct solution is aglobal security policy (Option A).
Global policiescan apply universally across zones, and an administrator can configure a final “deny all” rule to block any unmatched traffic.
ATP policy (Option B):Protects against advanced threats, not used for catch-all rule enforcement.
IDP policy (Option C):Focuses on intrusion detection and prevention signatures, not general traffic blocking.
Integrated user firewall policy (Option D):Applies policies based on user identity, but it does not provide a universal block across all services.
Correct Solution:Global security policy
[Reference:Juniper Networks –Global Security Policies, Junos OS Security Fundamentals., ]
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit