FCP_FGT_AD-7.6 · Question #127
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to…
The correct answer is A. Set the Destination address as Webserver in the Deny policy. D. Enable match-vip in the Deny policy. The scenario involves a VIP (Virtual IP) object representing the Webserver. By default, FortiGate firewall policies do not match VIP destination addresses in deny policies-VIP matching in deny policies requires 'match-vip' to be enabled (D). Without it, the deny policy is…
Question
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall configuration. An administrator created a Deny policy with default settings to deny Webserver access for Remote-User2. The policy should work such that Remote-User1 must be able to access the Webserver while preventing Remote-User2 from accessing the Webserver. Which two configuration changes can the administrator make to the policy to deny Webserver access for Remote-User2? (Choose two.)
Options
- ASet the Destination address as Webserver in the Deny policy.
- BDisable in the Deny policy.
- CSet the Destination address as Deny_IP in the Allow_access policy.
- DEnable match-vip in the Deny policy.
How the community answered
(26 responses)- A77% (20)
- B8% (2)
- C15% (4)
Explanation
The scenario involves a VIP (Virtual IP) object representing the Webserver. By default, FortiGate firewall policies do not match VIP destination addresses in deny policies-VIP matching in deny policies requires 'match-vip' to be enabled (D). Without it, the deny policy is bypassed for VIP-destined traffic. Additionally, setting the Destination address as Webserver (the VIP object) in the Deny policy (A) ensures the policy targets the correct destination. Option B (disabling something) is incomplete and not the fix. Option C targets the allow policy's destination, which would affect Remote-User1 and break the requirement for User1 to retain access.
Topics
Community Discussion
No community discussion yet for this question.