nerdexam
Fortinet

FCSS_NST_SE-7.6 · Question #17

What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)

The correct answer is C. Trusted host list misconfiguration. D. VIP or IP pool misconfiguration. VIP or IP pool misconfiguration. If a VIP or IP pool maps an address to the FortiGate itself, traffic destined for that address is treated as "local‑in," and iprope_in_check() will drop it when the FortiGate thinks it owns the Trusted host list misconfiguration. Management or…

Diagnose FortiGate Firewall Policies and NAT Issues

Question

What are two reasons you might see iprope_in_check() check failed, drop when using the debug flow? (Choose two.)

Options

  • APacket was dropped because of policy route misconfiguration.
  • BPacket was dropped because of traffic shaping.
  • CTrusted host list misconfiguration.
  • DVIP or IP pool misconfiguration.

How the community answered

(47 responses)
  • A
    6% (3)
  • B
    13% (6)
  • C
    81% (38)

Explanation

VIP or IP pool misconfiguration. If a VIP or IP pool maps an address to the FortiGate itself, traffic destined for that address is treated as "local‑in," and iprope_in_check() will drop it when the FortiGate thinks it owns the Trusted host list misconfiguration. Management or local‑in traffic (HTTPS, SSH, ping, etc.) hitting a FortiGate interface is subject to the trusted‑host list on that interface. If the source IP isn't permitted, iprope_in_check() will catch and drop it

Topics

#debug flow#iprope_in_check#trusted host#VIP misconfiguration

Community Discussion

No community discussion yet for this question.

Full FCSS_NST_SE-7.6 Practice