nerdexam
Fortinet

FCP_FGT_AD-7.4 · Question #90

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies configuration, VIP configuration, and IP pool configuration on the…

The correct answer is D. 10.200.1.100. NAT Configuration: The first firewall policy has NAT enabled using the configured IP pool. IP Pool Configuration: The IP pool is configured with an external IP range of 10.200.1.100. Source NAT: When traffic is being NATed, the source IP address is replaced with an IP from the…

Firewall Policies

Question

Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies configuration, VIP configuration, and IP pool configuration on the FortiGate device. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.1.10?

Exhibits

FCP_FGT_AD-7.4 question #90 exhibit 1
FCP_FGT_AD-7.4 question #90 exhibit 2
FCP_FGT_AD-7.4 question #90 exhibit 3
FCP_FGT_AD-7.4 question #90 exhibit 4

Options

  • A10.200.1.1
  • B10.200.1.10
  • C10.0.1.254
  • D10.200.1.100

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    14% (5)
  • C
    6% (2)
  • D
    74% (26)

Explanation

NAT Configuration: The first firewall policy has NAT enabled using the configured IP pool. IP Pool Configuration: The IP pool is configured with an external IP range of 10.200.1.100. Source NAT: When traffic is being NATed, the source IP address is replaced with an IP from the configured pool. In this scenario, the specific IP defined in the pool is 10.200.1.100. Thus, any internet-bound traffic from the workstation (10.0.1.10) will have its source IP address NATed to 10.200.1.100.

Topics

#SNAT#IP pool#NAT#firewall policy

Community Discussion

No community discussion yet for this question.

Full FCP_FGT_AD-7.4 Practice