nerdexam
Fortinet

NSE4_FGT-6.0 · Question #1

Examine this output from a debug flow: id=20085 trace_id=469 msg="vd-root: received a packet (proto=6, 66.111.121.84:80->10.200.1.200:49089) from port1. " id=20085 trace_id=469 msg="IPsec: no sa…

The correct answer is A. FortiGate received a TCP SYN/ACK packet. C. FortiGate routed the packet from port 3. See the full explanation below for the reasoning.

Question

Examine this output from a debug flow: id=20085 trace_id=469 msg="vd-root: received a packet (proto=6, 66.111.121.84:80->10.200.1.200:49089) from port1. " id=20085 trace_id=469 msg="IPsec: no sa found, dropping" id=20085 trace_id=469 msg="find an existing session, id-00007f60, reply direction" id=20085 trace_id=469 msg="Allow to D: 10.0.1.10->10.0.1.10 by policy-5" id=20085 trace_id=469 msg="find a route: 10.0.1.10->10.0.1.10 via port3" Which statements about the output are correct? (Choose two.)

Options

  • AFortiGate received a TCP SYN/ACK packet.
  • BThe source IP address of the packet was translated to 10.0.1.10.
  • CFortiGate routed the packet from port 3.
  • DThe packet was allowed by the firewall policy with the ID 00007f60.

How the community answered

(39 responses)
  • A
    79% (31)
  • B
    13% (5)
  • D
    8% (3)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.0 Practice