FCP_FGT_AD-7.4 · Question #63
Refer to the exhibits, which show a diagram of a FortiGate device connected to the network. VIP object configuration, and the firewall policy configuration. The WAN (port1) interface has the IP…
The correct answer is C. 10.200.3.1, 10.0.1.10, and 80, respectively. The source address remains 10.200.3.1 because FortiGate does not modify the source address by default unless NAT is applied (which is disabled in the policy). The destination address is translated to 10.0.1.10 by the VIP (Virtual IP) object, as this is the internal server…
Question
Refer to the exhibits, which show a diagram of a FortiGate device connected to the network. VIP object configuration, and the firewall policy configuration. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. If the host 10.200.3.1 sends a TCP SYN packet on port 8080 to 10.200.1.10, what will the source address, destination address, and destination port of the packet be at the time FortiGate forwards the packet to the destination?
Exhibits
Options
- A10.0.1.254, 10.200.1.10, and 8080, respectively
- B10.0.1.254, 10.0.1.10, and 80, respectively
- C10.200.3.1, 10.0.1.10, and 80, respectively
- D10.200.3.1, 10.0.1.10, and 8080, respectively
How the community answered
(34 responses)- A15% (5)
- B3% (1)
- C74% (25)
- D9% (3)
Explanation
The source address remains 10.200.3.1 because FortiGate does not modify the source address by default unless NAT is applied (which is disabled in the policy). The destination address is translated to 10.0.1.10 by the VIP (Virtual IP) object, as this is the internal server address mapped to the external IP 10.200.1.10. The destination port is translated from 8080 to 80 as per the port forwarding rule configured in the
Topics
Community Discussion
No community discussion yet for this question.


