FCP_FGT_AD-7.6 · Question #83
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device. The WAN (port2)…
The correct answer is C. 100.65.0.102. Traffic from the workstation 10.0.11.50 going to the internet matches the Internet(1) policy (LAN → WAN) which has NAT enabled and is configured to use the IP Pool. The IP pool specifies the external address 100.65.0.102. FortiGate will perform source NAT (SNAT) on the outbound…
Question
Refer to the exhibits. The exhibits show a diagram of a FortiGate device connected to the network, and the firewall policies, VIP, and IP pool configurations on the FortiGate device. The WAN (port2) interface has the IP address 100.65.0.101/24. The LAN (port4) interface has the IP address 10.0.11.254/24. The first firewall policy has NAT enabled using the IP pool. The second firewall policy is configured with a VIP as the destination address. Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.11.50?
Exhibits
Options
- A100.65.0.101
- B100.65.0.200
- C100.65.0.102
- D10.0.11.254
How the community answered
(33 responses)- A3% (1)
- B9% (3)
- C70% (23)
- D18% (6)
Explanation
Traffic from the workstation 10.0.11.50 going to the internet matches the Internet(1) policy (LAN → WAN) which has NAT enabled and is configured to use the IP Pool. The IP pool specifies the external address 100.65.0.102. FortiGate will perform source NAT (SNAT) on the outbound traffic, translating the source IP of the workstation to 100.65.0.102.
Topics
Community Discussion
No community discussion yet for this question.


