FCP_FGT_AD-7.6 · Question #82
Refer to the exhibits. A diagram of a FortiGate device connected to the network VIP object and firewall policy configurations are shown. The WAN (port2) interface has the IP address 100.65.0.101/24…
The correct answer is D. 100.65.1.111, 10.0.11.50, and 4443, respectively. The VIP object maps the external IP 100.65.0.200:443 to the internal server 10.0.11.50:4443. Since NAT is disabled on the firewall policy, the source IP is preserved. So, when host 100.65.1.111 connects to 100.65.0.200:443: - The source remains 100.65.1.111. - The destination…
Question
Exhibits
Options
- B100.65.1.111, 10.0.11.50 and 443, respectively
- C10.0.11.254, 100.65.0.200, and 443, respectively
- D100.65.1.111, 10.0.11.50, and 4443, respectively
How the community answered
(28 responses)- B7% (2)
- C14% (4)
- D79% (22)
Explanation
The VIP object maps the external IP 100.65.0.200:443 to the internal server 10.0.11.50:4443. Since NAT is disabled on the firewall policy, the source IP is preserved. So, when host 100.65.1.111 connects to 100.65.0.200:443: - The source remains 100.65.1.111. - The destination IP is translated to 10.0.11.50. - The destination port is translated to 4443.
Topics
Community Discussion
No community discussion yet for this question.

