nerdexam
Fortinet

NSE4_FGT-6.4 · Question #92

Examine this output from a debug flow: Why did the FortiGate drop the packet?

The correct answer is D. It matched the default implicit firewall policy. https://kb.fortinet.com/kb/documentLink.do?externalID=13900

Troubleshooting and Monitoring

Question

Examine this output from a debug flow:

Why did the FortiGate drop the packet?

Exhibit

NSE4_FGT-6.4 question #92 exhibit

Options

  • AThe next-hop IP address is unreachable.
  • BIt failed the RPF check.
  • CIt matched an explicitly configured firewall policy with the action DENY.
  • DIt matched the default implicit firewall policy.

How the community answered

(36 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    8% (3)
  • D
    75% (27)

Explanation

https://kb.fortinet.com/kb/documentLink.do?externalID=13900

Topics

#debug flow#packet drop#implicit deny policy#RPF check

Community Discussion

No community discussion yet for this question.

Full NSE4_FGT-6.4 Practice