FCP_FGT_AD-7.4 · Question #91
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy, and the sniffer CLI output on the FortiGate device. The WAN…
The correct answer is B. Create a new firewall policy before lnternet_Access for the webserver and apply the IP pool. D. Disable port forwarding on the VIP object. See the full explanation below for the reasoning.
Question
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, VIP configuration, firewall policy, and the sniffer CLI output on the FortiGate device. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. The webserver host (10.0.1.10) must use its VIP external IP address as the source NAT (SNAT) when it pings remote server (10.200.3.1). Which two statements are valid to achieve this goal? (Choose two.)
Exhibits
Options
- AEnable NAT on the Allow_access firewall policy.
- BCreate a new firewall policy before lnternet_Access for the webserver and apply the IP pool.
- CDisable NAT on the lnternet_Access firewall policy.
- DDisable port forwarding on the VIP object.
How the community answered
(34 responses)- A18% (6)
- B71% (24)
- C12% (4)
Community Discussion
No community discussion yet for this question.



