NSE4 · Question #187
Which of the following statements describes the method of creating a policy to block access to an FTP site?
The correct answer is B. Create a firewall policy with destination address set to the IP address of the FTP site, the Service. To block access to an FTP site on a FortiGate, create a firewall policy that specifies the FTP site's IP address as the destination and the FTP service, then set the action to deny.
Question
Which of the following statements describes the method of creating a policy to block access to an FTP site?
Options
- AEnable Web Filter URL blocking and add the URL of the FTP site to the URL Block list.
- BCreate a firewall policy with destination address set to the IP address of the FTP site, the Service
- CCreate a firewall policy with a protection profile containing the Block FTP option enabled.
- DNone of the above.
How the community answered
(41 responses)- A15% (6)
- B78% (32)
- C5% (2)
- D2% (1)
Why each option
To block access to an FTP site on a FortiGate, create a firewall policy that specifies the FTP site's IP address as the destination and the FTP service, then set the action to deny.
Web Filter URL blocking is primarily designed for HTTP/HTTPS traffic and is not typically used to block standard FTP protocol connections.
To block an FTP site, a specific firewall policy should be configured with the destination address set to the FTP server's IP address and the service set to FTP (TCP ports 20/21), with the policy action explicitly set to DENY.
While protection profiles apply various security features, there is no direct 'Block FTP' option within a general protection profile to block an entire FTP site; direct service blocking is handled at the firewall policy level.
Option B correctly describes a valid method for blocking an FTP site.
Concept tested: FortiGate firewall policy for service blocking
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/209193/about-firewall-policies
Topics
Community Discussion
No community discussion yet for this question.