Fortinet
NSE8_810 · Question #54
Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual…
The correct answer is B. config firewall central-snat-map edit 1 set protocol 1 next end. Explanation/Reference:
Network Infrastructure and Core FortiGate Features
Question
Click the Exhibit button. Central NAT was configured on a FortiGate firewall. A sniffer shows ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual IP(VIP) that was configured. Referring to the exhibit, which configuration will ensure that ICMP traffic is also translated?
Exhibit
Options
- Aconfig firewall ippool edit "secondry_ip" set arp-intf 'port1' next end
- Bconfig firewall central-snat-map edit 1 set protocol 1 next end
- Cconfig firewall central-snat-map edit 1 unset protocol next end
- Dconfig firewall central-snat-map edit 1 set orig-addr "all" next end
How the community answered
(26 responses)- A12% (3)
- B81% (21)
- C4% (1)
- D4% (1)
Explanation
Explanation/Reference:
Topics
#Central NAT#SNAT map#ICMP protocol#VIP
Community Discussion
No community discussion yet for this question.
