500-220 Exam QuestionsBrowse all questions from this exam

500-220 Exam - Question 12


Which two features and functions are supported when using an MX appliance in Passthrough mode? (Choose two.)

Show Answer
Correct Answer: AB

Using an MX appliance in Passthrough mode supports intrusion prevention and site-to-site VPN. Intrusion prevention provides security by monitoring network traffic for suspicious activity and potential threats, while site-to-site VPN allows secure connections between different geographic locations. Features like secondary uplinks, DHCP, and high availability are not supported in Passthrough mode.

Discussion

21 comments
Sign in to comment
azjlmpangOptions: AB
Jan 16, 2023

When in passthrough mode, the MX is best used for in-line: - Layer 3/7 firewall rules, traffic shaping, and analysis - Network asset discovery and reporting - Intrusion detection - Security and content filtering - Client and site-to-site VPN

jzzmthOptions: AE
Jul 17, 2024

Guys, I have this exact scenario in production right now and the answer is AE. We have two MX250s in passthrough mode for Intrusion PREVENTION and they are setup in HA. While they can technically do site-to-site VPN, but if they did, they would be considered CONCENTRATORS and not as pass-thru devices as per all Meraki official documentation as well as the description in the dashboard itself - thus AE is the most correct answer.

zylikeOptions: BE
Apr 24, 2023

The question was, which features ARE supported (not which are NOT), so: B and E https://documentation.meraki.com/MX/Networks_and_Routing/Passthrough_Mode_on_the_MX_Security_Appliance_and_Z-series_Teleworker_Gateway

CaptainPirate
Aug 6, 2023

champ according to the link you shared,the answer is A and B Configuration Differences There are a number of differences in configuration between Routed and passthrough modes on the MX: Secondary uplinks cannot be used for Internet connectivity. Thus Security & SD-WAN > Configure > SD-WAN & traffic shaping > Uplink configuration only has the option for limiting bandwidth on WAN 1. Site-to-site VPN can only operate in split-tunnel mode when configured as a hub. Traffic bound to VPN subnets must be directed to the MX. DHCP is no longer available. DHCP requests will simply pass through the MX. Cellular uplink is no longer available. VLANs cannot be configured. The MX/Z1 will act as a bridge between the Internet and LAN ports.

Jean226Options: BE
Jun 7, 2023

BE are correct

CaptainPirate
Aug 10, 2023

Intrusion prevention Yes Site-to-site VPN Yes Secondary uplinks No DHCP No High availability No

rnunes1110Options: AB
Nov 28, 2023

Correct: A and B

nyashacOptions: AB
Jan 3, 2024

When in passthrough mode, the MX is best used for in-line: Layer 3/7 firewall rules, traffic shaping, and analysis Network asset discovery and reporting Intrusion detection Security and content filtering Client and site-to-site VPN

XalaGyanOptions: BE
Feb 6, 2024

i have configured it for production and know that both B and E are possible. two VMX in HA and both in concentrator mode. Answers BE

AnyParka0BOptions: AB
May 10, 2024

A,B https://documentation.meraki.com/MX/Networks_and_Routing/Passthrough_Mode_on_the_MX_Security_Appliance_and_Z-series_Teleworker_Gateway

5448108
Jul 31, 2024

AB You can enable intrusion prevention by setting the Mode drop-down to Prevention under Security & SD-WAN > Configure > Threat protection > Intrusion detection and prevention. Traffic will be automatically blocked by best effort if it is detected as malicious based on the detection ruleset specified above. Protected Network section is used to controls the IP addresses or subnets of the systems protectied. Entries should be separated by commas or blank space(s). This will narrow down the subnets protected, it will protect only the subnets listed. Note: The Protected Network section is only available for Security Appliances in Passthrough mode. https://documentation.meraki.com/MX/Content_Filtering_and_Threat_Protection/Threat_Protection#:~:text=The%20MX's%20Intrusion%20Detection%20and,to%20ensure%20networks%20are%20safeguarded.

ilcarletto
Feb 16, 2025

B and E Passthrough mode supportes only Intrusion Detection and NOT Prevention. A is not correct

3ebcffaOptions: AE
Apr 9, 2025

It is A and E since we cannot have VLANs configured in passthrough VPN concentrator mode. In fact, I just checked right now that the Site to Site VPN is through the VLANs.

JerryKamb
Dec 8, 2022

https://documentation.meraki.com/MX/Networks_and_Routing/Passthrough_Mode_on_the_MX_Security_Appliance_and_Z-series_Teleworker_Gateway This should be Intrusion DETECTION not Prevention

shonda319
Mar 11, 2023

A and E. intrusion PREVENTION is not support HA in passthrough mode is support MX Warm Spare - High-Availability Pair - Cisco Meraki https://documentation.meraki.com/MX/Deployment_Guides/MX_Warm_Spare_-_High_Availability_Pair

blahblahblah2Options: AE
Apr 12, 2023

intrustion detection, it cannot do prevention so A and E

rnunes1110
Nov 7, 2023

A and B

fredbarron010
Nov 8, 2023

https://originalcerts.org/ Pass CCNA,CCNP,ITIL,Prince2,CITRIX,JUNIPER,AZURE,IBM,HP exams Pay After Results

Gilgamesh_SHAOptions: AB
Aug 7, 2024

The answer is A & B.

MPIAZZALOptions: AE
Oct 17, 2024

IPS + HA

sattoriOptions: BE
Dec 3, 2024

High availability can be inn both mode: Routed mode Passthrough or VPN Concentrator mode.

yottabyte_Options: AB
Jan 20, 2025

A & B In Passthrough Mode, since the Meraki device is not actively performing routing functions or managing network traffic in the same way, High Availability is NOT SUPPORTED.