Select the action that requires symmetrical traffic.
Comprehensive and Detailed Explanation From Exact Extract of Forescout Platform Administration and Deployment:
According to theForescout Administration Guide and Switch Plugin documentation, the action that requires symmetrical traffic is theEndpoint Address ACL action (C).
What 'Symmetrical Traffic' Means:
Symmetrical traffic refers to network traffic where CounterACT can monitor BOTH directions of communication:
Inbound- Traffic from the endpoint
Outbound- Traffic to the endpoint
This allows CounterACT to see the complete conversation flow.
Endpoint Address ACL Requirements:
According to the Switch Plugin documentation:
'The Endpoint Address ACL action applies an ACL that delivers blocking protection when endpoints connect to the network. Other benefits of Endpoint Address ACL include...'
For the Endpoint Address ACL to function properly, CounterACT must:
See bidirectional traffic- Monitor packets in both directions
Apply dynamic ACLs- Create filtering rules based on both source and destination
Verify endpoints- Ensure the endpoint IP/MAC matches expected patterns in both directions
Why Symmetrical Traffic is Required:
According to the documentation:
Endpoint Address ACLs work by:
Identifying the endpoint's MAC address and IP address through bidirectional observation
Creating switch ACLs that filter based on the endpoint's communication patterns
Verifying the endpoint is communicating in expected ways (symmetrically)
Without symmetrical traffic visibility, CounterACT cannot reliably identify and apply address-based filtering.
Why Other Options Do NOT Require Symmetrical Traffic:
A . Assign to VLAN- Only requires knowing the switch port; doesn't need traffic monitoring
B . WLAN block- Works at the wireless access point level without needing symmetrical traffic observation
D . Start SecureConnector- Deployment action that doesn't require traffic symmetry
Currently there are no comments in this discussion, be the first to comment!