Operations staff propose a firewall discard term to “secure” guest VLAN traffic the same way filter-based forwarding would. What is the key difference they must understand?
Select an answer to reveal the explanation.
Short Explanation
Same clipboard, different job. A discard term stamps “rejected” and throws the packet away. FBF uses that match to escort the flow into another routing table—like sending a visitor to a check-in desk instead of locking the door.
Full Explanation
Firewall filters can terminate in drop/reject actions or in filter-based forwarding actions that redirect matching packets into another routing instance. Ops that only discard guest traffic never deliver it to a captive or inspection path. FBF’s purpose is selective steering among forwarding contexts, not solely denial, and it commonly matches Layer-3/4 fields such as addresses, ports, and DSCP.