FCSS_NST_SE-7.4 · Question #17
What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)
The correct answer is C. Trusted host list misconfiguration. D. VIP or IP pool misconfiguration. VIP or IP pool misconfiguration. If a VIP or IP pool maps an address to the FortiGate itself, traffic destined for that address is treated as "local‑in," and iprope_in_check() will drop it when the FortiGate thinks it owns the Trusted host list misconfiguration. Management or…
Question
What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)
Options
- APacket was dropped because of policy route misconfiguration.
- BPacket was dropped because of traffic shaping.
- CTrusted host list misconfiguration.
- DVIP or IP pool misconfiguration.
How the community answered
(25 responses)- A8% (2)
- B20% (5)
- C72% (18)
Explanation
VIP or IP pool misconfiguration. If a VIP or IP pool maps an address to the FortiGate itself, traffic destined for that address is treated as "local‑in," and iprope_in_check() will drop it when the FortiGate thinks it owns the Trusted host list misconfiguration. Management or local‑in traffic (HTTPS, SSH, ping, etc.) hitting a FortiGate interface is subject to the trusted‑host list on that interface. If the source IP isn't permitted, iprope_in_check() will catch and drop it
Topics
Community Discussion
No community discussion yet for this question.