FCP_FGT_AD-7.6 · Question #47
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port1) interface has the…
The correct answer is C. 10.200.1.99. FortiGate applies Source NAT using an IP pool defined in the firewall policy. Based on the exhibits, the IP pool is configured with a range that includes 10.200.1.99, and the firewall policy for LAN-to-WAN traffic is set to use this pool. When Local-Client (10.0.1.10) sends…
Question
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, as well as the IP pool configuration and firewall policy objects. The WAN (port1) interface has the IP address 10.200.1.1/24. The LAN (port3) interface has the IP address 10.0.1.254/24. Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?
Exhibits
Options
- A10.200.1.1
- B10.200.1.149
- C10.200.1.99
- D10.200.1.49
How the community answered
(52 responses)- A8% (4)
- B21% (11)
- C67% (35)
- D4% (2)
Explanation
FortiGate applies Source NAT using an IP pool defined in the firewall policy. Based on the exhibits, the IP pool is configured with a range that includes 10.200.1.99, and the firewall policy for LAN-to-WAN traffic is set to use this pool. When Local-Client (10.0.1.10) sends traffic to Remote-FortiGate (10.200.3.1), FortiGate matches the firewall policy and translates the source IP to 10.200.1.99 from the pool. The WAN interface IP (10.200.1.1) would be used for interface-based SNAT (outgoing interface mode), not pool-based NAT. The other IP addresses (10.200.1.149 and 10.200.1.49) fall outside the pool range shown in the exhibits.
Topics
Community Discussion
No community discussion yet for this question.


