nerdexam
Fortinet

NSE6_FWB-6.4 · Question #39

Refer to the exhibit. FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to…

The correct answer is A. Enable the Use X-Forwarded-For setting on FortiWeb. C. Place FortiWeb in front of FortiADC. Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X- header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

Advanced Protection Features

Question

Refer to the exhibit. FortiADC is applying SNAT to all inbound traffic going to the servers. When an attack occurs, FortiWeb blocks traffic based on the 192.0.2.1 source IP address, which belongs to FortiADC. The setup is breaking all connectivity and genuine clients are not able to access the servers. What must the administrator do to avoid this problem? (Choose two.)

Exhibit

NSE6_FWB-6.4 question #39 exhibit

Options

  • AEnable the Use X-Forwarded-For setting on FortiWeb.
  • BNo Special configuration is required; connectivity will be re-established after the set timeout.
  • CPlace FortiWeb in front of FortiADC.
  • DEnable the Add X-Forwarded-For setting on FortiWeb.

How the community answered

(40 responses)
  • A
    60% (24)
  • B
    25% (10)
  • D
    15% (6)

Explanation

Configure your load balancer to insert or append to an X-Forwarded-For:, X-Real-IP:, or other HTTP X- header. Also configure FortiWeb to find the original attacker's or client's IP address in that HTTP header

Topics

#X-Forwarded-For#SNAT#source IP tracking#FortiADC integration

Community Discussion

No community discussion yet for this question.

Full NSE6_FWB-6.4 Practice