nerdexam
Fortinet

FCSS_NST_SE-7.4 · Question #27

Refer to the exhibit, which shows a FortiGate configuration. An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it…

The correct answer is A. Disable webfilter-force-off. The global "kill‑switch" for web filtering is turned on (set webfilter-force-off enable), which bypasses all web filters. You need to turn it off (for example with config system fortiguard -> set webfilter-force-off disable) so that your web filter profile will actually inspect…

FortiGuard Troubleshooting

Question

Refer to the exhibit, which shows a FortiGate configuration. An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy. What must the administrator do to fix the issue?

Exhibit

FCSS_NST_SE-7.4 question #27 exhibit

Options

  • ADisable webfilter-force-off.
  • BDisable webfilter-force-off at the VDOM level.
  • CSet sdns-server-ip to service.fortiguard.net.
  • DChange protocol to TCP and port to 53.

How the community answered

(48 responses)
  • A
    71% (34)
  • B
    4% (2)
  • C
    15% (7)
  • D
    10% (5)

Explanation

The global "kill‑switch" for web filtering is turned on (set webfilter-force-off enable), which bypasses all web filters. You need to turn it off (for example with config system fortiguard -> set webfilter-force-off disable) so that your web filter profile will actually inspect traffic.

Topics

#web filter#webfilter-force-off#traffic inspection#VDOM settings

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.4 Practice