A functional zone is used for special purposes, such as management interfaces. Juniper documentation states that currently only the management (MGT) functional zone is supported, which makes option A correct. The management functional zone is used for dedicated management interfaces and can be configured with host-inbound-traffic and screen options to protect management access, which makes option D correct. Option B is incorrect because functional zones are not groups of logical interfaces belonging to multiple security zones; they are special-purpose zones. Option C is incorrect because Juniper specifically states that the management functional zone cannot be specified in security policies, and traffic entering the management zone does not match policies.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit