FCP_FGT_AD-7.6 · Question #130
An administrator wants to ensure that a specific firewall policy on FortiGate is matched before any other policies for the same traffic. Which configuration change is most appropriate?
The correct answer is C. Move the policy higher in the policy list. FortiGate evaluates firewall policies in a strict top-to-bottom order, applying the first matching policy it encounters (first-match wins). Moving the target policy to a higher position in the policy list ensures it is evaluated before competing policies for the same traffic…
Question
An administrator wants to ensure that a specific firewall policy on FortiGate is matched before any other policies for the same traffic. Which configuration change is most appropriate?
Options
- AEnable central NAT
- BIncrease the policy ID number
- CMove the policy higher in the policy list
- DChange the policy schedule to always
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C93% (26)
Explanation
FortiGate evaluates firewall policies in a strict top-to-bottom order, applying the first matching policy it encounters (first-match wins). Moving the target policy to a higher position in the policy list ensures it is evaluated before competing policies for the same traffic. Policy ID numbers (B) are identifiers only and do not affect evaluation order-only position matters. Enabling central NAT (A) affects NAT processing, not policy match order. Changing the schedule (D) affects when the policy is active, not its match priority relative to other policies.
Topics
Community Discussion
No community discussion yet for this question.