ExamGecko
Question list
Search
Search

Question 97 - NSE4_FGT-7.2 discussion

Report
Export

FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.

In this scenario, what are two requirements for the VLAN ID? (Choose two.)

A.
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
Answers
A.
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in the same subnet.
B.
The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
Answers
B.
The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs.
C.
The two VLAN subinterfaces must have different VLAN IDs.
Answers
C.
The two VLAN subinterfaces must have different VLAN IDs.
D.
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Answers
D.
The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.
Suggested answer: B, C

Explanation:

https://community.fortinet.com/t5/FortiGate/Technical-Note-How-to-use-emac-vlan-to-share-the-same-VLAN/ta-p/192843?externalID=FD43883

When FortiGate is operating in NAT mode, it means that it uses network address translation (NAT) to modify the source or destination IP addresses of the traffic passing through it1. NAT mode allows FortiGate to hide the IP addresses of the internal network from the external network, and to conserve IP addresses by using a single public IP address for multiple private IP addresses1.

A virtual LAN (VLAN) subinterface is a logical interface that allows traffic from different VLANs to enter and exit the FortiGate unit2. A VLAN subinterface is created by adding a VLAN ID to a physical interface or an aggregate interface2. A VLAN ID is a numerical identifier that distinguishes one VLAN from another2.

In this scenario, there are two requirements for the VLAN ID of the VLAN subinterfaces added to the same physical interface:

The two VLAN subinterfaces must have different VLAN IDs. This is because the VLAN ID is used to tag the traffic with the appropriate VLAN information, and to separate the traffic into different VLANs2. If the two VLAN subinterfaces have the same VLAN ID, they will not be able to distinguish the traffic from each other, and they will not be able to forward the traffic to the correct destination.

The two VLAN subinterfaces can have the same VLAN ID, only if they belong to different VDOMs. This is because VDOMs are virtual instances of FortiGate that can have their own interfaces, policies, and routing tables3. Each VDOM operates independently from other VDOMs, and can have its own VLAN subinterfaces with different or identical VLAN IDs3. However, this requires inter-VDOM links to allow traffic between different VDOMs3.

asked 18/09/2024
Avtandili Tsagareishvili
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first