nerdexam
Fortinet

NSE8_812 · Question #115

Central NAT was configured on a FortiGate firewall. A sniffer ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual IP (VIP) that was configured…

The correct answer is B. config firewall central-snat-map edit 1 unset protocol next end. See the full explanation below for the reasoning.

Question

Central NAT was configured on a FortiGate firewall. A sniffer ICMP packets out to a host on the Internet egresses with the port1 IP address instead of the virtual IP (VIP) that was configured Referring to the exhibit, which configuration change will ensure that ICMP traffic is also translated?

Options

  • Aconfig firewall central-snat-map edit 1 set protocol 1 next end
  • Bconfig firewall central-snat-map edit 1 unset protocol next end
  • Cconfig firewall ippool edit "secondary_ip" set arp-intf 'port1' next end
  • Dconfig firewall central-snat-map edit 1 set orig-addr "all" next end

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    79% (22)
  • C
    11% (3)
  • D
    7% (2)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice