FCP_FGT_AD-7.6 · Question #84
Refer to the exhibit. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)
The correct answer is B. A packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is C. A packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is. With strict RPF enabled, the FortiGate checks that the return path to the source would use the same interface the packet arrived on defencedev.com . For a source of 10.10.10.10, the routing table shows the return path is via the 10.10.10.0/24 route on port 3. If such a packet…
Question
Refer to the exhibit. Based on the routing table shown in the exhibit, which two statements are true? (Choose two.)
Exhibit
Options
- AA packet with the source IP address arriving on port3 is allowed if strict RPF is
- BA packet with the source IP address 10.100.110.10 arriving on port2 is allowed if strict RPF is
- CA packet with the source IP address 10.0.13.10 arriving on port2 is allowed if strict RPF is
- DA packet with the source IP address 10.10.10.10 arriving on port2 is allowed if strict RPF is
How the community answered
(27 responses)- A15% (4)
- B78% (21)
- D7% (2)
Explanation
With strict RPF enabled, the FortiGate checks that the return path to the source would use the same interface the packet arrived on defencedev.com . For a source of 10.10.10.10, the routing table shows the return path is via the 10.10.10.0/24 route on port 3. If such a packet arrives on port 2, the return path doesn’t match and strict RPF When strict RPF is disabled, FortiGate uses loose RPF, which permits a packet as long as there is a route back to the source defencedev.com . In this case the only route back to 10.100.110.10 is the default route via port 2, not the incoming port 3. Exam guidance takes a conservative view that, without a more specific route to the source (and with no RPF enabled on that interface), such a packet would not be accepted.
Topics
Community Discussion
No community discussion yet for this question.
