nerdexam
Fortinet

NSE4 · Question #474

Your Linux email server runs on a non-standard port number, port 2525. Which statement is true?

The correct answer is B. To apply IPS to traffic to that server, you must configured FortiGate SMTP proxy to listen on. For FortiGate's IPS to effectively inspect application-layer traffic on non-standard ports, a specific proxy for that protocol must be configured to listen on the non-standard port.

Submitted by parkjh· Apr 18, 2026Security Profiles and Content Inspection

Question

Your Linux email server runs on a non-standard port number, port 2525. Which statement is true?

Options

  • AIPS cannot scan that traffic for SMTP anomalies because of the non-standard port number.
  • BTo apply IPS to traffic to that server, you must configured FortiGate SMTP proxy to listen on
  • CIPS will apply all SMTP signatures, regardless of whether they apply to clients or servers.
  • DProtocol decoders automatically detect SMTP and scan for matches with appropriate IPS

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    74% (39)
  • C
    15% (8)
  • D
    4% (2)

Why each option

For FortiGate's IPS to effectively inspect application-layer traffic on non-standard ports, a specific proxy for that protocol must be configured to listen on the non-standard port.

AIPS cannot scan that traffic for SMTP anomalies because of the non-standard port number.

IPS can scan traffic on non-standard ports, but it requires explicit configuration of the relevant protocol proxy to identify the application layer protocol correctly.

BTo apply IPS to traffic to that server, you must configured FortiGate SMTP proxy to listen onCorrect

To ensure IPS can correctly identify and inspect SMTP traffic on a non-standard port like 2525, you must configure the FortiGate's SMTP proxy to listen on that specific port.

CIPS will apply all SMTP signatures, regardless of whether they apply to clients or servers.

IPS applies signatures based on identified protocols; without proper protocol identification, it cannot reliably apply SMTP-specific signatures.

DProtocol decoders automatically detect SMTP and scan for matches with appropriate IPS

While some decoders use heuristics, relying solely on automatic detection for non-standard ports is often insufficient for comprehensive IPS inspection and requires explicit proxy configuration.

Concept tested: FortiGate IPS/Proxy inspection on non-standard ports

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/524874/applying-ips-to-traffic-on-non-standard-ports

Topics

#IPS#SMTP inspection#Non-standard ports#Protocol options

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice