Fortinet
NSE4_FGT-6.4 · Question #16
Which of the following statements about central NAT are true? (Choose two.)
The correct answer is A. IP tool references must be removed from existing firewall policies before enabling central NAT. B. Central NAT can be enabled or disabled from the CLI only. When the central nat is enabled from the cli the Central SNAT and the DNAT & Virtual IPS become available in the Policy & Objects side menu. Also you must remove the VIP and IP Pool
Firewall Policies
Question
Which of the following statements about central NAT are true? (Choose two.)
Options
- AIP tool references must be removed from existing firewall policies before enabling central NAT.
- BCentral NAT can be enabled or disabled from the CLI only.
- CSource NAT, using central NAT, requires at least one central SNAT policy.
- DDestination NAT, using central NAT, requires a VIP object as the destination address in a firewall.
How the community answered
(15 responses)- A80% (12)
- C13% (2)
- D7% (1)
Explanation
When the central nat is enabled from the cli the Central SNAT and the DNAT & Virtual IPS become available in the Policy & Objects side menu. Also you must remove the VIP and IP Pool
Topics
#central NAT#SNAT policy#VIP#CLI configuration
Community Discussion
No community discussion yet for this question.