nerdexam
Fortinet

FCSS_LED_AR-7.6 · Question #55

When the MAC address of a device is placed in quarantine on FortiSwitch, what happens to its egress traffic?

The correct answer is A. Traffic is sent to an access VLAN. When a device'sMAC address is quarantinedon a FortiSwitch (via FortiLink NAC, fabric automation, or manual quarantine), FortiSwitch enforces quarantine using thequarantine VLAN, also called theaccess VLANinside FortiSwitch NAC operations. FortiSwitch behavior is defined in LAN…

FortiSwitch Deployment and Configuration

Question

When the MAC address of a device is placed in quarantine on FortiSwitch, what happens to its egress traffic?

Options

  • ATraffic is sent to an access VLAN.
  • BTraffic is assigned to the native VLAN.
  • CTraffic is sent as untagged traffic.
  • DTraffic is sent to an allowed VLAN.

How the community answered

(24 responses)
  • A
    88% (21)
  • C
    8% (2)
  • D
    4% (1)

Explanation

When a device'sMAC address is quarantinedon a FortiSwitch (via FortiLink NAC, fabric automation, or manual quarantine), FortiSwitch enforces quarantine using thequarantine VLAN, also called theaccess VLANinside FortiSwitch NAC operations. FortiSwitch behavior is defined in LAN Edge documentation: Quarantined devices are moved into an"access VLAN" reserved for isolation. This VLAN isstatically defined on the FortiGate NAC policy, and switch ports dynamically reassign the quarantined MAC into that VLAN. All egress traffic from the quarantined MAC is forced into this VLAN, preventing access to the production network. Thus, the correct description is: Traffic is sent to an access VLAN.

Topics

#MAC quarantine#FortiSwitch#access VLAN#traffic isolation

Community Discussion

No community discussion yet for this question.

Full FCSS_LED_AR-7.6 Practice