nerdexam
Fortinet

NSE4_FGT-6.4 · Question #143

Consider the topology: Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server. An administrator is investigating a problem where an application establishes a Telnet session…

The correct answer is A. Set the maximum session TTL value for the TELNET service object. B. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not. See the full explanation below for the reasoning.

Question

Consider the topology:

Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server. An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout. The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN. What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)

Options

  • ASet the maximum session TTL value for the TELNET service object.
  • BSet the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not
  • CCreate a new service object for TELNET and set the maximum session TTL.
  • DCreate a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic,

How the community answered

(26 responses)
  • A
    77% (20)
  • C
    8% (2)
  • D
    15% (4)

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.4 Practice