ExamGecko
Question list
Search
Search

Question 150 - NSE4_FGT-7.2 discussion

Report
Export

If Internet Service is already selected as Destination in a firewall policy, which other configuration object can be selected for the Destination field of a firewall policy?

A.
IP address
Answers
A.
IP address
B.
No other object can be added
Answers
B.
No other object can be added
C.
FQDN address
Answers
C.
FQDN address
D.
User or User Group
Answers
D.
User or User Group
Suggested answer: B

Explanation:

FortiGate Security 7.2 Study Guide (p.59): 'When configuring your firewall policy, you can use Internet Service as the destination in a firewall policy, which contains all the IP addresses, ports, and protocols used by that service. For the same reason, you cannot mix regular address objects with ISDB objects, and you cannot select services on a firewall policy. The ISDB objects already have services information, which is hardcoded.'

This is true because Internet Service is a special type of destination object that can only be used alone in a firewall policy. Internet Service is a feature that allows FortiGate to identify and filter traffic based on the internet service or application that it belongs to, such as Facebook, YouTube, Skype, etc. Internet Service uses a database of IP addresses and ports that are associated with each internet service or application, and updates it regularly from FortiGuard. When Internet Service is selected as the destination in a firewall policy, FortiGate will match the traffic to the corresponding internet service or application, and apply the appropriate action and security profiles to it. However, Internet Service cannot be combined with any other destination object, such as IP address, FQDN address, user or user group, etc., as this would create a conflict or ambiguity in the firewall policy. Therefore, no other object can be added if Internet Service is already selected as the destination in a firewall policy

asked 18/09/2024
Swapnil Salunke
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first