NSE4 · Question #316
Which statements correctly describe transparent mode operation? (Choose three.)
The correct answer is C. It permits inline traffic inspection and firewalling without changing the IP scheme of the network. D. Ethernet packets are forwarded based on destination MAC addresses, not IP addresses. E. The FortiGate acts as transparent bridge and forwards traffic at Layer-2. In transparent mode, a FortiGate operates as a Layer-2 bridge, forwarding traffic based on MAC addresses, which allows it to inspect and firewall inline traffic without requiring changes to the network's IP addressing scheme.
Question
Which statements correctly describe transparent mode operation? (Choose three.)
Options
- AAll interfaces of the transparent mode FortiGate device must be on different IP subnets.
- BThe transparent FortiGate is visible to network hosts in an IP traceroute.
- CIt permits inline traffic inspection and firewalling without changing the IP scheme of the network.
- DEthernet packets are forwarded based on destination MAC addresses, not IP addresses.
- EThe FortiGate acts as transparent bridge and forwards traffic at Layer-2.
How the community answered
(30 responses)- A3% (1)
- B7% (2)
- C90% (27)
Why each option
In transparent mode, a FortiGate operates as a Layer-2 bridge, forwarding traffic based on MAC addresses, which allows it to inspect and firewall inline traffic without requiring changes to the network's IP addressing scheme.
In transparent mode, all interfaces that form the bridge must be on the *same* IP subnet, as the device is forwarding traffic at Layer 2 within that segment.
Because a transparent mode FortiGate operates at Layer 2 and does not perform IP routing, it is typically invisible to network hosts in an IP traceroute.
Transparent mode allows the FortiGate to be inserted into an existing network segment to perform security functions like inspection and firewalling without requiring any changes to the IP addressing or routing configuration of the network.
In transparent mode, the FortiGate functions as a Layer-2 bridge, meaning it processes and forwards Ethernet frames based on their destination MAC addresses, rather than routing based on IP addresses.
The FortiGate in transparent mode behaves like an invisible Layer-2 bridge, connecting two network segments and passing traffic between them while applying security policies.
Concept tested: FortiGate transparent mode operation
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/464817/operation-modes
Topics
Community Discussion
No community discussion yet for this question.