NSE4 · Question #85
Which header field can be used in a firewall policy for traffic matching?
The correct answer is A. ICMP type and code. FortiGate firewall policies can utilize ICMP type and code fields to match specific types of ICMP traffic, allowing granular control over diagnostic or error messages.
Question
Which header field can be used in a firewall policy for traffic matching?
Options
- AICMP type and code.
- BDSCP.
- CTCP window size.
- DTCP sequence number.
How the community answered
(38 responses)- A87% (33)
- B3% (1)
- C8% (3)
- D3% (1)
Why each option
FortiGate firewall policies can utilize ICMP type and code fields to match specific types of ICMP traffic, allowing granular control over diagnostic or error messages.
FortiGate firewall policies allow for deep inspection and filtering of ICMP traffic by specifying the ICMP type (e.g., Echo Request, Destination Unreachable) and code (e.g., Network Unreachable, Host Unreachable), enabling precise control over what diagnostic messages are permitted.
DSCP (Differentiated Services Code Point) is used for Quality of Service (QoS) marking, not typically as a direct matching criterion in standard FortiGate firewall policies for allowing or denying traffic.
TCP window size is a dynamic field used for flow control and is not a static header field used for traffic matching in FortiGate firewall policies.
TCP sequence numbers are dynamic values used to order TCP segments for reliable delivery and are not used as a static matching criterion in FortiGate firewall policies.
Concept tested: FortiGate firewall policy matching criteria
Source: https://docs.fortinet.com/document/fortigate/7.4.0/cli-reference/64367/config-firewall-policy
Topics
Community Discussion
No community discussion yet for this question.