NSE4 · Question #190
If no firewall policy is specified between two FortiGate interfaces and zones are not used, which of the following statements describes the action taken on traffic flowing between these interfaces?
The correct answer is A. The traffic is blocked. If no firewall policy is explicitly configured between two FortiGate interfaces, all traffic attempting to flow between them will be implicitly blocked.
Question
If no firewall policy is specified between two FortiGate interfaces and zones are not used, which of the following statements describes the action taken on traffic flowing between these interfaces?
Options
- AThe traffic is blocked.
- BThe traffic is passed.
- CThe traffic is passed and logged.
- DThe traffic is blocked and logged.
How the community answered
(54 responses)- A93% (50)
- B2% (1)
- C2% (1)
- D4% (2)
Why each option
If no firewall policy is explicitly configured between two FortiGate interfaces, all traffic attempting to flow between them will be implicitly blocked.
The FortiGate operates on an implicit deny principle; any traffic that does not explicitly match an allowed firewall policy between interfaces or zones is automatically blocked by default.
Traffic is not passed by default; an explicit firewall policy is always required to allow traffic to flow between interfaces.
Traffic is not passed by default, and logging of implicitly denied traffic is not enabled without specific configuration; the fundamental action is to block.
While the traffic is blocked, logging of implicitly denied traffic is not enabled by default and requires separate configuration; the primary action is the block.
Concept tested: FortiGate implicit deny firewall behavior
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/209193/about-firewall-policies
Topics
Community Discussion
No community discussion yet for this question.