I'll go with B Looking at the Firewall rules, Layer 3 processing comes first and the MX ships with a default L3 Implicit Allow. When a rule is added, it is added as either an L3 Allow or Deny, depending on the policy and is inserted above the default. So L3 Allow/Deny is processed first, then L3 implicit allow. L7 Firewall rules are only created with Deny as the policy option.
... View more