🔥 3-day streak
Cisco CCNP Data Center DCCOR (350-601)71 / 136
Question 71 of 136

A data center engineer must restrict traffic on a Nexus 9000 leaf so that internal hosts in 10.10.0.0/16 can initiate TCP connections to an external web service at 203.0.113.50, but the external service must NOT be able to initiate new connections back into the data center. The engineer configures an ingress IPv4 ACL on the external-facing interface to filter inbound (returning) traffic. Which ACL entry correctly permits only the return traffic for sessions the internal hosts initiated, using the stateless NX-OS ACL capability?

Reviewed for accuracy · Report an issueNext question