nerdexam
Fortinet

NSE8_810 · Question #54

Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual…

The correct answer is B. config firewall central-snat-map edit 1 set protocol 1 next end. Explanation/Reference:

Network Infrastructure and Core FortiGate Features

Question

Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual IP(VIP) that was configured. Referring to the exhibit, which configuration will ensure that ICMP traffic is also translated?

Exhibit

NSE8_810 question #54 exhibit

Options

  • Aconfig firewall ippool edit "secondry_ip" set arp-intf 'port1' next end
  • Bconfig firewall central-snat-map edit 1 set protocol 1 next end
  • Cconfig firewall central-snat-map edit 1 unset protocol next end
  • Dconfig firewall central-snat-map edit 1 set orig-addr "all" next end

How the community answered

(26 responses)
  • A
    12% (3)
  • B
    81% (21)
  • C
    4% (1)
  • D
    4% (1)

Explanation

Explanation/Reference:

Topics

#Central NAT#SNAT map#ICMP protocol#VIP

Community Discussion

No community discussion yet for this question.

Full NSE8_810 Practice