FCSS_EFW_AD-7.6 · Question #75
An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Choose two.)
The correct answer is B. Configure central source network address translation (SNAT), if NAT is required. D. Specify an SSLISSH inspection profile on a consolidated policy. In FortiGate's NGFW policy-based mode, NAT is not configured inline within individual firewall policies - instead, it is handled separately via central SNAT policies (B). Additionally, policy-based mode uses consolidated policies (combining IPv4/IPv6), and an SSL/SSH inspection…
Question
An administrator is configuring application control with FortiGate running in next-generation firewall (NGFW) policy-based mode. Which two actions must the administrator take? (Choose two.)
Options
- AConfigure the action as quarantine, if an application requires feedback to prevent instability.
- BConfigure central source network address translation (SNAT), if NAT is required.
- CCreate an application control profile and apply the profile to a firewall policy.
- DSpecify an SSLISSH inspection profile on a consolidated policy.
How the community answered
(34 responses)- A9% (3)
- B74% (25)
- C18% (6)
Explanation
In FortiGate's NGFW policy-based mode, NAT is not configured inline within individual firewall policies - instead, it is handled separately via central SNAT policies (B). Additionally, policy-based mode uses consolidated policies (combining IPv4/IPv6), and an SSL/SSH inspection profile is mandatory on these policies for application identification to function correctly on encrypted traffic (D).
Why the distractors are wrong:
- A is incorrect - quarantine is not the recommended action for applications requiring feedback; this describes an unrelated use case and is not a required configuration step in this mode.
- C is incorrect - creating an application control profile and attaching it to a policy is the workflow for profile-based mode, not policy-based mode. In policy-based mode, application visibility is built directly into the consolidated policy without a separate profile.
Memory tip: Think of policy-based mode as "centralized and consolidated" - NAT goes to a central SNAT table, and traffic policies are consolidated (hence needing the SSL/SSH profile there). If you remember those two "C" words, B and D follow naturally.
Topics
Community Discussion
No community discussion yet for this question.