NSE4 · Question #426
Which of the following statements are correct differences between NAT/route and transparent mode? (Choose two.)
The correct answer is A. In transparent mode, interfaces do not have IP addresses. C. Static routers are only used in NAT/route mode. Transparent mode FortiGates act as Layer 2 bridges without needing IP addresses on their interfaces for data forwarding, and static routes are primarily used in NAT/route mode for Layer 3 routing.
Question
Which of the following statements are correct differences between NAT/route and transparent mode? (Choose two.)
Options
- AIn transparent mode, interfaces do not have IP addresses.
- BFirewall polices are only used in NAT/ route mode.
- CStatic routers are only used in NAT/route mode.
- DOnly transparent mode permits inline traffic inspection at layer 2.
How the community answered
(17 responses)- A94% (16)
- B6% (1)
Why each option
Transparent mode FortiGates act as Layer 2 bridges without needing IP addresses on their interfaces for data forwarding, and static routes are primarily used in NAT/route mode for Layer 3 routing.
In transparent mode, the FortiGate functions as a Layer 2 bridge, forwarding traffic based on MAC addresses, and therefore its interfaces do not require IP addresses within the data path.
Firewall policies are essential in both NAT/route mode and transparent mode to define security rules, control traffic flow, and apply security profiles.
Static routes are Layer 3 constructs used for directing IP traffic, and since transparent mode FortiGates operate at Layer 2 and do not perform routing for user traffic, static routes are specifically used in NAT/route mode.
Both transparent mode (Layer 2) and NAT/route mode (Layer 3, when inline) permit inline traffic inspection, making this statement incorrect for implying it's exclusive to transparent mode.
Concept tested: FortiGate Operating Mode Differences (NAT/Route vs Transparent)
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/523490/operating-modes
Topics
Community Discussion
No community discussion yet for this question.