FCSS_SDW_AR-7.4 · Question #59
Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?
The correct answer is A. FortiGate routes the traffic flow according to the FIB. On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25…
Question
Refer to the exhibit. How does FortiGate handle the traffic with the source IP 10.0.1.130 and the destination IP 128.66.0 125?
Exhibit
Options
- AFortiGate routes the traffic flow according to the FIB.
- BFortiGate load balances the traffic flow through port1 and port2.
- CFortiGate drops the traffic flow.
- DFortiGate steers the traffic flow through port2.
How the community answered
(42 responses)- A79% (33)
- B5% (2)
- C2% (1)
- D14% (6)
Explanation
On FortiGate, a policy route (PBR) with action deny does not drop the traffic outright. Instead, it prevents the traffic from being steered by that policy route, and the packet is then handed back to the regular routing lookup (FIB): Source 10.0.1.130 matches 10.0.1.128/25 Destination 128.66.0.125 matches 128.66.0.0/24 Router policy says action deny → do not use this policy route Result: FortiGate falls back to the FIB (normal routing table).
Topics
Community Discussion
No community discussion yet for this question.
