ExamGecko
Question list
Search
Search

Question 134 - NSE4_FGT-7.2 discussion

Report
Export

Refer to the exhibit.

The exhibit shows a diagram of a FortiGate device connected to the network, the firewall policy and VIP configuration on the FortiGate device, and the routing table on the ISP router.

When the administrator tries to access the web server public address (203.0.113.2) from the internet, the connection times out. At the same time, the administrator runs a sniffer on FortiGate to capture incoming web traffic to the server and does not see any output.

Based on the information shown in the exhibit, what configuration change must the administrator make to fix the connectivity issue?

A.
Configure a loopback interface with address 203.0.113.2/32.
Answers
A.
Configure a loopback interface with address 203.0.113.2/32.
B.
In the VIP configuration, enable arp-reply.
Answers
B.
In the VIP configuration, enable arp-reply.
C.
Enable port forwarding on the server to map the external service port to the internal service port.
Answers
C.
Enable port forwarding on the server to map the external service port to the internal service port.
D.
In the firewall policy configuration, enable match-vip.
Answers
D.
In the firewall policy configuration, enable match-vip.
Suggested answer: B

Explanation:

FortiGate Security 7.2 Study Guide (p.115): 'Enabling ARP reply is usually not required in most networks because the routing tables on the adjacent devices contain the correct next hop information, so the networks are reachable. However, sometimes the routing configuration is not fully correct, and having ARP reply enabled can solve the issue for you. For this reason, it's a best practice to keep ARP reply enabled.'

asked 18/09/2024
Jatuchot Siriwongsilp
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first