NSE4 · Question #105
For traffic that does match any configured firewall policy, what is the default action taken by the FortiGate?
The correct answer is C. The traffic is blocked and no log is generated. By default, any traffic that does not match an explicitly configured firewall policy on a FortiGate unit is implicitly denied and dropped without generating a log.
Question
For traffic that does match any configured firewall policy, what is the default action taken by the FortiGate?
Options
- AThe traffic is allowed and no log is generated.
- BThe traffic is allowed and logged.
- CThe traffic is blocked and no log is generated.
- DThe traffic is blocked and logged.
How the community answered
(54 responses)- A2% (1)
- B2% (1)
- C91% (49)
- D6% (3)
Why each option
By default, any traffic that does not match an explicitly configured firewall policy on a FortiGate unit is implicitly denied and dropped without generating a log.
The default action is to deny traffic that doesn't match a policy, not allow it.
The default action is to deny traffic, not allow it, and logging is not enabled for the implicit deny.
FortiGate devices operate on an explicit permit principle; if traffic does not match any configured firewall policy, it is silently dropped by the implicit deny rule at the end of the policy list, and no log is generated for this implicit action by default.
While the traffic is blocked, it is not logged by default when dropped by the implicit deny rule; explicit logging requires a deny policy with logging enabled.
Concept tested: FortiGate implicit deny policy
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/700813/firewall-policies
Topics
Community Discussion
No community discussion yet for this question.