NSE4 · Question #492
Which is true about incoming and outgoing interfaces in firewall policies?
The correct answer is D. Source and destination interfaces are mandatory. In FortiGate firewall policies, specifying both incoming and outgoing interfaces is a mandatory requirement to correctly define the traffic flow subject to policy enforcement.
Question
Which is true about incoming and outgoing interfaces in firewall policies?
Options
- AA physical interface may not be used.
- BA zone may not be used.
- CMultiple interfaces may not be used for both incoming and outgoing.
- DSource and destination interfaces are mandatory.
How the community answered
(27 responses)- A7% (2)
- C4% (1)
- D89% (24)
Why each option
In FortiGate firewall policies, specifying both incoming and outgoing interfaces is a mandatory requirement to correctly define the traffic flow subject to policy enforcement.
Physical interfaces are commonly used as both incoming and outgoing interfaces in firewall policies to define traffic flow between physical network segments.
Zones, which are logical groupings of multiple physical or virtual interfaces, are frequently used as incoming or outgoing interfaces to simplify policy management.
FortiGate allows the selection of multiple interfaces or zones for both incoming and outgoing traffic within a single firewall policy, providing flexibility in defining traffic flows.
For every FortiGate firewall policy, administrators must explicitly define both the incoming interface (where traffic enters the FortiGate) and the outgoing interface (where traffic exits), establishing the exact path for which the policy applies.
Concept tested: FortiGate firewall policy interface requirements
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/608269/creating-a-firewall-policy
Topics
Community Discussion
No community discussion yet for this question.