NSE4 · Question #84
Which firewall objects can be included in the Destination Address field of a firewall policy? (Choose three.)
The correct answer is B. Virtual IP address. C. IP address. D. IP address group. FortiGate firewall policies allow the use of specific IP addresses, IP address groups, and Virtual IP (VIP) addresses in the Destination Address field for traffic matching.
Question
Which firewall objects can be included in the Destination Address field of a firewall policy? (Choose three.)
Options
- AIP address pool.
- BVirtual IP address.
- CIP address.
- DIP address group.
- EMAC address.
How the community answered
(51 responses)- A2% (1)
- B94% (48)
- E4% (2)
Why each option
FortiGate firewall policies allow the use of specific IP addresses, IP address groups, and Virtual IP (VIP) addresses in the Destination Address field for traffic matching.
IP address pools are used for Source NAT (SNAT) or Central NAT (CNAT) to assign outbound IP addresses, not as destination addresses in a firewall policy itself.
Virtual IP (VIP) addresses represent a public IP that translates to an internal private IP, often used for inbound services, and are valid objects to specify as a destination for traffic coming into the FortiGate.
An individual IP address, whether a host address or a subnet, is a fundamental object that can be directly specified as the destination for traffic in a firewall policy.
An IP address group allows administrators to combine multiple IP addresses or subnets into a single object, simplifying policy management when traffic needs to be directed to or from a collection of destinations.
MAC addresses operate at Layer 2 and are not typically used in Layer 3/4 firewall policy destination fields, which primarily focus on IP addresses and ports.
Concept tested: FortiGate firewall policy destination objects
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/209673/firewall-policies
Topics
Community Discussion
No community discussion yet for this question.