NSE4 · Question #17
Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with a firewall policy? (Choose two.)
The correct answer is B. Only traffic matching the application control signature is shaped. C. Can limit the bandwidth usage of heavy traffic applications. When traffic shaping is applied within an application control sensor and linked to a firewall policy, it specifically shapes only the traffic identified by the application control signature, and it is highly effective at limiting the bandwidth usage of identified heavy-traffic…
Question
Which statements are true regarding traffic shaping that is applied in an application sensor, and associated with a firewall policy? (Choose two.)
Options
- AShared traffic shaping cannot be used.
- BOnly traffic matching the application control signature is shaped.
- CCan limit the bandwidth usage of heavy traffic applications.
- DPer-IP traffic shaping cannot be used.
How the community answered
(18 responses)- A6% (1)
- B89% (16)
- D6% (1)
Why each option
When traffic shaping is applied within an application control sensor and linked to a firewall policy, it specifically shapes only the traffic identified by the application control signature, and it is highly effective at limiting the bandwidth usage of identified heavy-traffic applications.
Both shared and per-IP traffic shapers can be used with application control; there is no restriction preventing shared shapers.
Traffic shapers applied directly within an application control profile are granular; they only affect the specific traffic streams that are identified and matched by the application control signature configured in that profile.
A primary use case for applying traffic shaping through application control is to manage and limit the bandwidth consumed by specific applications, especially those known for high bandwidth usage like streaming, peer-to-peer, or gaming.
Per-IP traffic shapers can be applied when defining traffic shaping in an application control profile, allowing for granular control of bandwidth per source or destination IP for specific applications.
Concept tested: FortiGate application control traffic shaping characteristics
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/336495/configuring-application-control
Topics
Community Discussion
No community discussion yet for this question.