What are the two modes of operations in Security Appliance?
A. The PIX Security Appliance can operate in two different firewall modes: • Routed mode—In routed mode, the PIX has IP addresses assigned to its interfaces and acts as a router hop for packets that pass through it. All traffic inspection and forwarding decisions are based on Layer 3 parameters. This is how PIX Firewall versions earlier than 7.0 operate. • Transparent mode—In transparent mode the PIX does not have IP addresses assigned to its interfaces. Instead it acts as a Layer 2 bridge that maintains a MAC address table and makes forwarding decisions based on that. The use of full extended IP access lists is still available and the firewall can inspect IP activity at any layer. In this mode of operation the PIX is often referred to as a “bump in the wire” or “stealth firewall”. There are other significant differences as to how transparent mode operates in comparison to routed mode: • Only two interfaces are supported—inside and outside • NAT is not supported or required since the P