nerdexam
Fortinet

NSE8_812 · Question #205

You configured a FortiADC in a one-arm deployment load balancing two IIS Windows servers in a DSR behind an existing FortiGate. The virtual IP and firewall policy in the FortiGate has been properly…

The correct answer is A. Packet Forwarding Method is set to DNAT on the FortiADC but the FortiGate is blocking asymmetric traffic. C. Packet Forwarding Method is set to Direct Routing on the FortiADC but DSR is not configured on the IIS Server. See the full explanation below for the reasoning.

Question

You configured a FortiADC in a one-arm deployment load balancing two IIS Windows servers in a DSR behind an existing FortiGate. The virtual IP and firewall policy in the FortiGate has been properly configured to point incoming web traffic to the correct FortiADC virtual server IP. The FortiADC and IIS server logs shows incoming traffic, but the client devices did not receive any response traffic. Which two options are possible reasons for this behavior? (Choose two.)

Options

  • APacket Forwarding Method is set to DNAT on the FortiADC but the FortiGate is blocking asymmetric traffic.
  • BPacket Forwarding Method is set to Full NAT on the FortiADC but X-Forwarded-For is not enabled.
  • CPacket Forwarding Method is set to Direct Routing on the FortiADC but DSR is not configured on the IIS Server.
  • DPacket Forwarding Method is set to Full NAT on the FortiADC but the NAT Source Pool List is set to the FortiADC interface IP.

How the community answered

(18 responses)
  • A
    78% (14)
  • B
    17% (3)
  • D
    6% (1)

Community Discussion

No community discussion yet for this question.

Full NSE8_812 Practice