Cisco CCNA (200-301)Network FundamentalsMedium

A network administrator configures a firewall to allow outbound HTTP requests from internal hosts but does not create any explicit inbound rule for the return traffic. Users can still browse external websites successfully. Which firewall characteristic explains this behavior?

  1. AThe firewall is stateful and automatically permits return traffic for established sessions.
  2. BThe firewall is performing stateless packet filtering.
  3. CThe firewall has NAT overload disabled for outbound sessions.
  4. DThe firewall is operating in transparent mode.
Show answer & explanation

Correct answer: A. The firewall is stateful and automatically permits return traffic for established sessions.

A stateful firewall tracks the state of active connections in a state table; once an outbound connection is permitted, the firewall automatically allows the corresponding return traffic without requiring a separate inbound rule, unlike a stateless firewall which evaluates every packet independently.

Why the other options are wrong

  • B. Stateless filtering evaluates each packet independently and would require an explicit inbound rule for return traffic.
  • C. NAT overload (PAT) relates to address translation, not to why return traffic is permitted without an inbound rule.
  • D. Transparent mode refers to Layer 2 firewall deployment without IP addressing changes, unrelated to session tracking.

Stateful Firewall

A firewall that tracks the state of active network connections in a state table and automatically permits return traffic belonging to an established, allowed session.

  • Maintains a state table of active connections
  • Automatically allows return traffic for permitted outbound sessions
  • Contrasts with stateless firewalls, which require explicit rules for both directions

Memory trick: Stateful firewalls remember the conversation, stateless ones forget instantly.

More Network Fundamentals questions