FCSS_CDS_AR-7.6 · Question #45
Refer to the exhibit. In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to the FortiGate VM in…
The correct answer is A. Add a route with your local internet public IP address as the destination and the internet gateway C. Add a route to the destination 0.0.0.0/0 with the transit gateway as the target. E. Deploy an internet gateway, attach it to the Customer VPC, and then associate an EIP with port1. Keep all other outbound internet traffic going from the Customer VPC FortiGate to the Security VPC via the TGW by setting 0.0.0.0/0 -> TGW. Add a specific route for your admin public IP -> IGW so return traffic for HTTPS management goes directly to the internet. Attach an…
Question
Refer to the exhibit. In your Amazon Web Services (AWS), you must allow inbound HTTPS access to the Customer VPC FortiGate VM from the internet. However, your HTTPS connection to the FortiGate VM in the Customer VPC is not successful. Also, you must ensure that the Customer VPC FortiGate VM sends all the outbound internet traffic through the Security VPC. How do you correct this issue with minimal configuration changes? (Choose three.)
Exhibit
Options
- AAdd a route with your local internet public IP address as the destination and the internet gateway
- BAdd a route with your local internet public IP address as the destination and the transit gateway
- CAdd a route to the destination 0.0.0.0/0 with the transit gateway as the target.
- DDeploy an internet gateway, associate an EIP with the Customer VPC private subnet, and then
- EDeploy an internet gateway, attach it to the Customer VPC, and then associate an EIP with port1
How the community answered
(35 responses)- A54% (19)
- B29% (10)
- D17% (6)
Explanation
Keep all other outbound internet traffic going from the Customer VPC FortiGate to the Security VPC via the TGW by setting 0.0.0.0/0 -> TGW. Add a specific route for your admin public IP -> IGW so return traffic for HTTPS management goes directly to the internet. Attach an Internet Gateway to the Customer VPC and assign an EIP to FortiGate port1 to allow inbound HTTPS from the internet.
Topics
Community Discussion
No community discussion yet for this question.
