nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #12

Refer to the exhibit. Assuming a default configuration, which three statements are true? (Choose three.)

The correct answer is B. User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table. C. User A: Pass. The default static route through wan1 passes the RPF check regardless of the E. User C: Fail. There is no route to 10.0.4.63 using port1 in the touting table. User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table. Since 95.56.234.24 doesn't match 10.0.2.0/24, traffic arriving on wan2 would have to be routed out via the default gateway on wan1-and strict reverse‑path checks will drop it. User C: Fail. There…

Routing

Question

Refer to the exhibit. Assuming a default configuration, which three statements are true? (Choose three.)

Exhibit

FCSS_NST_SE-7.4 question #12 exhibit

Options

  • AStrict RPF is enabled by default.
  • BUser B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table.
  • CUser A: Pass. The default static route through wan1 passes the RPF check regardless of the
  • DUser B: Pass. FortiGate will use asymmetric routing using wan1 to reply to traffic for
  • EUser C: Fail. There is no route to 10.0.4.63 using port1 in the touting table.

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    77% (27)
  • D
    17% (6)

Explanation

User B: Fail. There is no route to 95.56.234.24 using wan2 in the routing table. Since 95.56.234.24 doesn't match 10.0.2.0/24, traffic arriving on wan2 would have to be routed out via the default gateway on wan1-and strict reverse‑path checks will drop it. User C: Fail. There is no route to 10.0.4.63 using port1 in the routing table. Port1 only knows about 10.0.3.0/24-without a static route or proxy ARP for 10.0.4.0/24, the FortiGate won't accept or route that traffic. User A: Pass. The default static route through wan1 passes the RPF check regardless of the source IP address. Traffic from 71.234.149.16 hits wan1, and the return path is also via wan1 (the default route), so it

Topics

#RPF#reverse path forwarding#asymmetric routing#strict RPF

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice