nerdexam
Fortinet

NSE7_PBC-7.2 · Question #84

Refer to the exhibit. An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the…

The correct answer is D. Check the inbound network security group rules. Considering the situation where the administrator is unable to access the FortiGate VM using its public IP address and no traffic is reaching the FortiGate's external interface, the administrator should check: D. Check the inbound network security group rules. Network Security…

FortiGate-VM in Public Cloud

Question

Refer to the exhibit. An administrator has deployed a FortiGate VM in Amazon Web Services (AWS) and is trying to access it using its public IP address from their local computer. However, the connection is not successful and at the same time FortiGate is not receiving any HTTPS or SSH traffic to its external interface. What should the administrator check for possible issue?

Exhibit

NSE7_PBC-7.2 question #84 exhibit

Options

  • ARun a debug flow to check any network ACLs
  • BCheck the FortiGate firewall policies
  • CCheck the FortiGate instance ID
  • DCheck the inbound network security group rules

How the community answered

(25 responses)
  • A
    12% (3)
  • B
    12% (3)
  • C
    4% (1)
  • D
    72% (18)

Explanation

Considering the situation where the administrator is unable to access the FortiGate VM using its public IP address and no traffic is reaching the FortiGate's external interface, the administrator should check: D. Check the inbound network security group rules. Network Security Group Rules: AWS uses security groups as a virtual firewall that controls inbound and outbound traffic to AWS resources such as EC2 instances. If the FortiGate VM's public interface is not receiving HTTPS or SSH traffic, it's likely because the inbound security group rules associated with that interface are not allowing access on the necessary ports (HTTPS - port 443, SSH - port 22). Troubleshooting: The administrator should verify that the security group rules for the FortiGate VM's network interface allow inbound traffic on the specific ports used for management access. If these rules are absent or misconfigured, the intended traffic will be blocked, resulting in the inability to connect.

Topics

#AWS security groups#FortiGate VM#connectivity troubleshooting#network ACL

Community Discussion

No community discussion yet for this question.

Full NSE7_PBC-7.2 Practice