NSE4 · Question #34
Which statements correctly describe transparent mode operation? (Choose three.)
The correct answer is A. The FortiGate acts as transparent bridge and forwards traffic at Layer-2. B. Ethernet packets are forwarded based on destination MAC addresses, NOT IP addresses. D. Permits inline traffic inspection and firewalling without changing the IP scheme of the network. Transparent mode configures the FortiGate as a Layer 2 bridge that forwards Ethernet packets based on MAC addresses, enabling inline traffic inspection and firewalling without altering the network's IP addressing scheme or being visible in an IP traceroute.
Question
Which statements correctly describe transparent mode operation? (Choose three.)
Options
- AThe FortiGate acts as transparent bridge and forwards traffic at Layer-2.
- BEthernet packets are forwarded based on destination MAC addresses, NOT IP addresses.
- CThe transparent FortiGate is clearly visible to network hosts in an IP trace route.
- DPermits inline traffic inspection and firewalling without changing the IP scheme of the network.
- EAll interfaces of the transparent mode FortiGate device must be on different IP subnets.
How the community answered
(29 responses)- A93% (27)
- C3% (1)
- E3% (1)
Why each option
Transparent mode configures the FortiGate as a Layer 2 bridge that forwards Ethernet packets based on MAC addresses, enabling inline traffic inspection and firewalling without altering the network's IP addressing scheme or being visible in an IP traceroute.
In transparent mode, the FortiGate operates as a Layer 2 bridge, forwarding Ethernet frames between its interfaces based on MAC addresses rather than performing Layer 3 routing.
As a Layer 2 device, a transparent mode FortiGate inspects and forwards Ethernet packets based on their destination MAC addresses, similar to how a network switch operates.
A key characteristic of transparent mode is that the FortiGate functions as an invisible Layer 2 bridge, meaning it does not appear as a hop in an IP trace route.
Transparent mode allows a FortiGate to be deployed invisibly within an existing network segment, inspecting and applying firewall policies to traffic without requiring changes to the IP addressing or routing configuration.
In transparent mode, all interfaces of the FortiGate typically reside within the same IP subnet, bridging traffic between segments of that subnet.
Concept tested: FortiGate transparent mode functionality
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/33912/transparent-mode
Topics
Community Discussion
No community discussion yet for this question.