ECMS MX Security Appliances and Firewall 2 — Questions and Answers
Question 1: Which VPN topology type in Meraki Auto VPN allows all branch sites to communicate directly with each other?
- Hub-and-spoke
- Full mesh (Correct answer)
- Star topology
- Partial mesh
Correct answer: Full mesh
Full mesh Auto VPN topology establishes direct IPsec tunnels between every pair of spoke sites, enabling branch-to-branch traffic without traversing the hub.
Question 2: What is the function of the Meraki MX Intrusion Prevention System (IPS)?
- Blocks all encrypted HTTPS traffic
- Detects and blocks network exploits using Sourcefire rule sets (Correct answer)
- Scans only outbound traffic for data exfiltration
- Replaces the need for firewall rules entirely
Correct answer: Detects and blocks network exploits using Sourcefire rule sets
The Meraki MX IPS uses Sourcefire (now Cisco Talos) rule sets to detect and block known network exploits and intrusion attempts in real time.
Question 3: How does Meraki MX handle failover when dual WAN uplinks are configured?
- Manual administrator intervention is required
- It uses BGP to reroute traffic automatically
- It monitors uplink health and automatically fails over to the secondary WAN (Correct answer)
- It requires a separate failover appliance
Correct answer: It monitors uplink health and automatically fails over to the secondary WAN
Meraki MX continuously monitors WAN uplink health using active/passive probing and automatically switches to the secondary uplink upon failure.
Question 4: What is the purpose of configuring outbound firewall rules on a Meraki MX appliance?
- To control traffic leaving the local network toward the internet or WAN (Correct answer)
- To block inbound traffic from reaching LAN hosts
- To define VPN split tunneling rules
- To prioritize traffic for QoS marking
Correct answer: To control traffic leaving the local network toward the internet or WAN
Outbound firewall rules on the MX control which local clients can communicate with which external destinations, based on source, destination, and protocol.
Question 5: Which Meraki MX capability provides remote users with secure access to corporate resources using a client-side software agent?
- Auto VPN
- Client VPN (IPsec/L2TP)
- Meraki Systems Manager EMM
- Teleworker VPN with AnyConnect (Correct answer)
Correct answer: Teleworker VPN with AnyConnect
Meraki MX supports Cisco AnyConnect for teleworker VPN, providing secure SSL/TLS-based remote access for mobile and remote users.
Question 6: In a Meraki MX deployment, what does enabling 'Split Tunneling' on a Client VPN connection mean?
- All client traffic is routed through the VPN tunnel
- Only traffic destined for corporate resources uses the VPN; internet traffic exits locally (Correct answer)
- The VPN tunnel is split across two WAN interfaces
- Two separate VPN tunnels are established simultaneously
Correct answer: Only traffic destined for corporate resources uses the VPN; internet traffic exits locally
Split tunneling allows VPN clients to route only corporate-destined traffic through the tunnel while sending internet traffic directly through the local ISP.
Which VPN topology type in Meraki Auto VPN allows all branch sites to communicate directly with each other?