ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 43 - NSE7_PBC-7.2 discussion

Report
Export

Refer to the exhibit.

An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface

What should the administrator check for possible issue?

A.
Run a debug flow to check any network ACLs
Answers
A.
Run a debug flow to check any network ACLs
B.
Check the FortiGate firewall policies
Answers
B.
Check the FortiGate firewall policies
C.
Check the FortiGate instance ID
Answers
C.
Check the FortiGate instance ID
D.
Check the inbound network security group rules
Answers
D.
Check the inbound network security group rules
Suggested answer: D

Explanation:

Considering the situation where the administrator is unable to access the FortiGate VM using its public IP address and no traffic is reaching the FortiGate's external interface, the administrator should check:

D) Check the inbound network security group rules.

Network Security Group Rules: AWS uses security groups as a virtual firewall that controls inbound and outbound traffic to AWS resources such as EC2 instances. If the FortiGate VM's public interface is not receiving HTTPS or SSH traffic, it's likely because the inbound security group rules associated with that interface are not allowing access on the necessary ports (HTTPS - port 443, SSH - port 22).

Troubleshooting: The administrator should verify that the security group rules for the FortiGate VM's network interface allow inbound traffic on the specific ports used for management access. If these rules are absent or misconfigured, the intended traffic will be blocked, resulting in the inability to connect.

asked 18/09/2024
Jean Ducasse
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first