nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #58

Refer to the exhibit. An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the…

The correct answer is B. Check the inbound rules of the security groups. Since the FortiGate VM is not receiving any HTTPS or SSH traffic at all, the most likely cause is that the inbound rules of the AWS Security Group attached to the FortiGate instance are not permitting traffic on ports 22 (SSH) or 443 (HTTPS). If the Security Group blocks…

Troubleshooting and Optimization

Question

Refer to the exhibit. An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the connection is not successful, and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface. What should the administrator check for possible issue?

Exhibit

FCSS_CDS_AR-7.6 question #58 exhibit

Options

  • ACheck the debug flow for any network ACLs.
  • BCheck the inbound rules of the security groups.
  • CCheck the FortiGate firewall policies.
  • DCheck the FortiGate instance ID.

How the community answered

(44 responses)
  • A
    11% (5)
  • B
    80% (35)
  • C
    7% (3)
  • D
    2% (1)

Explanation

Since the FortiGate VM is not receiving any HTTPS or SSH traffic at all, the most likely cause is that the inbound rules of the AWS Security Group attached to the FortiGate instance are not permitting traffic on ports 22 (SSH) or 443 (HTTPS). If the Security Group blocks traffic, packets never reach FortiGate, which explains the absence of captured traffic.

Topics

#AWS security groups#inbound rules#FortiGate access#troubleshooting connectivity

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice