NSE7_NST-7.2 Exam QuestionsBrowse all questions from this exam

NSE7_NST-7.2 Exam - Question 2


Refer to the exhibit.

FortiGate has already been configured with a firewall policy that allows all ICMP traffic to flow from port1 to port3.

Which changes must the administrator perform to ensure the server at 10.4.0.1/24 receives the echo reply from the laptop at 10.1.0.1/24?

Show Answer
Correct Answer:

Discussion

2 comments
Sign in to comment
tuky88Option: A
Dec 9, 2024

See page 371 in the Network Support Engineer Study Guide - By default - if an echo request does not pass through Fortigate but the response does, the packet is dropped. There are scenarios where this might be needed, you can then use the "set asymroute enable" in "config system settings".

evdwOption: A
Dec 16, 2024

If a FortiGate recognizes the response packets, but not the requests, it blocks the packets as invalid. This is asymmetric routing. By default, a FortiGate blocks packets or drops the session when this happens. FortiGate can be configured to permit asymmetric routing