NSE4 · Question #199
Which of the following statements correctly describes how a FortiGate unit functions in Transparent mode?
The correct answer is B. An IP address is used to manage the FortiGate unit but this IP address is not associated with a. In Transparent mode, a FortiGate unit acts as a Layer 2 bridge, forwarding traffic without modifying IP addresses, and is managed via a dedicated management IP address that isn't directly bound to a physical interface for data plane operations.
Question
Which of the following statements correctly describes how a FortiGate unit functions in Transparent mode?
Options
- ATo manage the FortiGate unit, one of the interfaces must be designated as the management
- BAn IP address is used to manage the FortiGate unit but this IP address is not associated with a
- CThe FortiGate unit must use public IP addresses on the internal and external networks.
- DThe FortiGate unit uses private IP addresses on the internal network but hides them using
How the community answered
(33 responses)- B94% (31)
- C3% (1)
- D3% (1)
Why each option
In Transparent mode, a FortiGate unit acts as a Layer 2 bridge, forwarding traffic without modifying IP addresses, and is managed via a dedicated management IP address that isn't directly bound to a physical interface for data plane operations.
While management does occur over an interface, it's not 'designated' as a management interface in the sense of having a data plane IP that traffic routes through; it's a logical management IP.
In Transparent mode, the FortiGate acts as a Layer 2 bridge, inspecting traffic without routing. It needs an IP address for management, but this management IP is not associated with any specific physical interface for data plane forwarding; instead, it is a management IP that allows administrators to access the device without interfering with the bridged traffic flow.
Transparent mode operates at Layer 2 and does not perform routing or NAT, thus the concept of public/private IP addresses on internal/external networks for the FortiGate itself is not applicable to its data plane operation.
This describes NAT/Route mode functionality, where the FortiGate uses private IP addresses internally and performs NAT, which is not how Transparent mode operates.
Concept tested: FortiGate Transparent mode functionality
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/468894/operating-modes
Topics
Community Discussion
No community discussion yet for this question.