Fortinet
NSE4_FGT-6.0 · Question #1
Examine this output from a debug flow: id=20085 trace_id=469 msg="vd-root: received a packet (proto=6, 66.111.121.84:80->10.200.1.200:49089) from port1. " id=20085 trace_id=469 msg="IPsec: no sa…
The correct answer is A. FortiGate received a TCP SYN/ACK packet. C. FortiGate routed the packet from port 3. See the full explanation below for the reasoning.
Question
Examine this output from a debug flow:
id=20085 trace_id=469 msg="vd-root: received a packet (proto=6, 66.111.121.84:80->10.200.1.200:49089) from port1. "
id=20085 trace_id=469 msg="IPsec: no sa found, dropping"
id=20085 trace_id=469 msg="find an existing session, id-00007f60, reply direction"
id=20085 trace_id=469 msg="Allow to D: 10.0.1.10->10.0.1.10 by policy-5"
id=20085 trace_id=469 msg="find a route: 10.0.1.10->10.0.1.10 via port3"
Which statements about the output are correct? (Choose two.)
Options
- AFortiGate received a TCP SYN/ACK packet.
- BThe source IP address of the packet was translated to 10.0.1.10.
- CFortiGate routed the packet from port 3.
- DThe packet was allowed by the firewall policy with the ID 00007f60.
How the community answered
(39 responses)- A79% (31)
- B13% (5)
- D8% (3)
Community Discussion
No community discussion yet for this question.