NSE4 · Question #16
How do you configure a FortiGate to apply traffic shaping to P2P traffic, such as BitTorrent?
The correct answer is A. Apply a traffic shaper to a BitTorrent entry in an application control list, which is then applied to a. To apply traffic shaping to specific application traffic like BitTorrent, you configure an application control profile, select the desired application, assign a traffic shaper, and then apply this profile to a firewall policy.
Question
How do you configure a FortiGate to apply traffic shaping to P2P traffic, such as BitTorrent?
Options
- AApply a traffic shaper to a BitTorrent entry in an application control list, which is then applied to a
- BEnable the shape option in a firewall policy with service set to BitTorrent.
- CDefine a DLP rule to match against BitTorrent traffic and include the rule in a DLP sensor with
- DApply a traffic shaper to a protocol options profile.
How the community answered
(15 responses)- A80% (12)
- B7% (1)
- D13% (2)
Why each option
To apply traffic shaping to specific application traffic like BitTorrent, you configure an application control profile, select the desired application, assign a traffic shaper, and then apply this profile to a firewall policy.
FortiGate integrates traffic shapers with application control. To shape specific application traffic like BitTorrent, you must create or edit an application control profile, locate the BitTorrent application signature, and then associate a configured traffic shaper directly with that application entry. The application control profile is then applied within a firewall policy.
Firewall policies allow applying traffic shaping, but the Service field primarily identifies port/protocol combinations, not specific applications like BitTorrent which require deep packet inspection from application control.
DLP (Data Loss Prevention) is designed for inspecting content for sensitive data, not for identifying and shaping specific application traffic like BitTorrent. While DLP can apply actions, traffic shaping is not its primary mechanism for application control.
Protocol options profiles are used for settings like HTTP inspection, IPS, and proxy options, but they do not directly provide the mechanism to apply traffic shapers to specific applications identified via signatures.
Concept tested: FortiGate traffic shaping with application control
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/336495/configuring-application-control
Topics
Community Discussion
No community discussion yet for this question.