nerdexam
Fortinet

NSE4 · Question #541

How do you configure a FortiGate to do traffic shaping of P2P traffic, such as BitTorrent?

The correct answer is B. Enable the shape option in a firewall policy with service set to BitTorrent. To traffic shape P2P traffic like BitTorrent, you must create a firewall policy that identifies the application and then enable and configure the 'shape' option directly within that policy.

Submitted by andres_qro· Apr 18, 2026Firewall Policies and Authentication

Question

How do you configure a FortiGate to do traffic shaping of P2P traffic, such as BitTorrent?

Options

  • AApply an application control profile allowing BitTorrent to a firewall policy and configure a traffic
  • BEnable the shape option in a firewall policy with service set to BitTorrent.
  • CApply a traffic shaper to a BitTorrent entry in the SSL/SSH inspection profile.
  • DApply a traffic shaper to a protocol options profile.

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    87% (40)
  • C
    9% (4)
  • D
    2% (1)

Why each option

To traffic shape P2P traffic like BitTorrent, you must create a firewall policy that identifies the application and then enable and configure the 'shape' option directly within that policy.

AApply an application control profile allowing BitTorrent to a firewall policy and configure a traffic

An application control profile helps identify BitTorrent, but the traffic shaping parameters themselves are applied and configured within the firewall policy, not directly through the application control profile or as a separate traffic object.

BEnable the shape option in a firewall policy with service set to BitTorrent.Correct

Traffic shaping for specific applications like BitTorrent is configured within a firewall policy by first identifying the application (e.g., via an application control signature or custom service) and then enabling and defining a traffic shaper directly in the policy's settings.

CApply a traffic shaper to a BitTorrent entry in the SSL/SSH inspection profile.

SSL/SSH inspection profiles manage the decryption and inspection behavior of encrypted traffic, but they do not provide functionality for applying traffic shapers to specific applications.

DApply a traffic shaper to a protocol options profile.

Protocol options profiles are used for various deep inspection settings for specific protocols (e.g., HTTP, FTP) but are not the mechanism for applying traffic shapers.

Concept tested: FortiGate application traffic shaping

Source: https://docs.fortinet.com/document/fortigate/7.4.0/fortios-handbook/705708/traffic-shaping

Topics

#Traffic Shaping#Firewall Policies#Application Control#P2P Traffic

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice