nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 102


Refer to the exhibits.

Exhibit A shows a network diagram. Exhibit B shows the central SNAT policy and IP pool configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24.

The LAN (port3) interface has the IP address 10.0.1.254/24.

A firewall policy is configured to allow all destinations from LAN (port3) to WAN (port1).

Central NAT is enabled, so NAT settings from matching central SNAT policies will be applied.

Which IP address will be used to source NAT (SNAT) the traffic, if the user on Local-Client (10.0.1.10) pings the IP address of Remote-FortiGate (10.200.3.1)?

Show Answer
Correct Answer: A

The IP address 10.200.1.99 will be used to source NAT the traffic because the user on Local-Client is pinging, which uses the ICMP protocol. According to Exhibit B, the central SNAT policy for protocol number 1 (ICMP) specifies the translated address as 'SNAT-Remote1,' which corresponds to the external IP range 10.200.1.99.

Discussion

8 comments
Sign in to comment
besi05Option: A
Jul 19, 2023

A is correct , pings is ICMP so protocol 1. Protocol 1 is enabled on access list id 2 which has destination address SNAT-remote 1

Halmonte0780Option: A
Jul 24, 2023

It's A because of the protocol number. Ping = icmp Ping is ICMP protocol - protocol number = 1 => SNAT policy ID 1 is policy that used. => Translated address is "SNAT-Remote1" that 10.200.1.99

D1360_1304Option: A
Aug 7, 2023

A. Correct - is for ICMP B. Incorrect - C. Incorrect - is for TCP protocol D. Incorrect - is for IGMP protocol

TakumiOption: A
Jul 19, 2023

The real answer es A

TakumiOption: D
Jul 18, 2023

The answer is D

raydel92Option: A
Sep 14, 2023

A. 10.200.1.99 Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

Jumpy007Option: A
Sep 16, 2023

Protocol number 1 ICMP Internet Control Message Protocol https://www.fortinetguru.com/2018/12/protocol-number/

darkdante24Option: A
Jan 16, 2024

A is correct, look at the pictures carefully they have made it complicated on purpose.