NSE4 · Question #107
The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below…
The correct answer is D. DNS Internet access is always allowed, even for users that has not authenticated. In FortiGate configurations using firewall policy authentication, DNS Internet access is typically always allowed, even for users who have not yet authenticated.
Question
The FortiGate port1 is connected to the Internet. The FortiGate port2 is connected to the internal network. Examine the firewall configuration shown in the exhibit; then answer the question below. Based on the firewall configuration illustrated in the exhibit, which statement is correct?
Exhibit
Options
- AA user that has not authenticated can access the Internet using any protocol that does not trigger
- BA user that has not authenticated can access the Internet using any protocol except HTTP,
- CA user must authenticate using the HTTP, HTTPS, SSH, FTP, or Telnet protocol before they can
- DDNS Internet access is always allowed, even for users that has not authenticated.
How the community answered
(25 responses)- B4% (1)
- C8% (2)
- D88% (22)
Why each option
In FortiGate configurations using firewall policy authentication, DNS Internet access is typically always allowed, even for users who have not yet authenticated.
Without the exhibit, it is not possible to confirm that any protocol not triggering authentication would be allowed, as other policies could block them.
This statement is too broad; specific protocols would be allowed or denied based on the detailed policies in the exhibit, which is not provided.
This statement is incorrect because, for functional purposes, DNS access is almost always allowed prior to full user authentication.
In typical FortiGate deployments that utilize firewall policy authentication, DNS traffic (UDP port 53) is often permitted for unauthenticated users through a specific policy to ensure that devices can resolve hostnames necessary for network access and the authentication portal itself.
Concept tested: FortiGate firewall policy for unauthenticated DNS access
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/700813/firewall-policies
Topics
Community Discussion
No community discussion yet for this question.
