FCSS_NST_SE-7.4 · Question #59
Refer to the exhibit, which a network topology and a partial routing table. FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3…
The correct answer is C. A firewall policy that allows all ICMP traffic from port3 to port1. Because FortiGuard is a stateful firewall it still needs an explicit policy to allow the return ICMP replies, even though the session was initiated from port1. By adding a firewall policy permitting ICMP from port3 back to port1, the echoreplies arriving on port3 will be…
Question
Refer to the exhibit, which a network topology and a partial routing table. FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3. Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?
Options
- AEnable asymmetric routing under config system settings.
- BChange the configuration from strict RPF check mode to feasible RPF check mode.
- CA firewall policy that allows all ICMP traffic from port3 to port1.
- DModify the default gateway on the laptop from 10.1.0.2 to 10.2.0.2.
How the community answered
(48 responses)- A10% (5)
- B4% (2)
- C79% (38)
- D6% (3)
Explanation
Because FortiGuard is a stateful firewall it still needs an explicit policy to allow the return ICMP replies, even though the session was initiated from port1. By adding a firewall policy permitting ICMP from port3 back to port1, the echoreplies arriving on port3 will be forwarded to the laptop on port1. Without this reverse policy, the server's replies would be dropped at the FortiGate. This ensures bidirectional ICMP flow between 10.1.0.1 and 10.4.0.1.
Topics
Community Discussion
No community discussion yet for this question.