nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 104


Refer to the exhibit.

In the network shown in the exhibit, the web client cannot connect to the HTTP web server. The administrator runs the FortiGate built-in sniffer and gets the output shown in the exhibit.

What should the administrator do next, to troubleshoot the problem?

Show Answer
Correct Answer: A

In the setup shown, the web client is sending SYN packets to the web server. These packets are observed entering and exiting through FortiGate's port3 interface. However, there is no indication that these packets are reaching the web server since there are no SYN-ACK responses from the server in the sniffer output. To troubleshoot further, it is necessary to determine why the SYN packets are not reaching the web server or if they are being dropped by FortiGate. Executing a debug flow on FortiGate will provide detailed insights into the packet's path through the firewall, including policy checks and any reason for dropping packets. This information is crucial for identifying any issues with FortiGate's configuration or rules that might be preventing the web client from connecting to the web server.

Discussion

11 comments
Sign in to comment
crose
Aug 31, 2023

I can't see questions 105-109????

DanteHn
Sep 29, 2023

Same here.

DreBod
Dec 25, 2023

Same here

Imanism
Feb 4, 2024

Same here

alig0r
Feb 28, 2024

same here

raydel92Option: A
Sep 14, 2023

A. Execute a debug flow. FortiGate Infrastructure 7.2 Study Guide (p.357): "If FortiGate is dropping packets, can a packet capture (sniffer) be used to identify the reason? To find the cause, you should use the debug (packet) flow." Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html

Sam_2121
Jan 7, 2024

Same here, can see up to 104

Halmonte0780Option: A
Jul 24, 2023

Answer is A, because sniffer shows the ingressing and egressing packets . but we cannot see dropped packets by fortigate in a sniffer. Debugging can show the packets are not entering for any reasons caused by fortigate. So believe if a packed is reached to fortigate and dropped , debug will show us. Debug flow will definitely provide the reason why the packets are dropped. Infrastructure guide 7.2, pages 357

Knowledge33Option: D
Sep 24, 2023

The answer is D, not A. It's not mentionned the packet is blocked somewhere. As we can see the sniffer command, we capture packet on all interfaces. Packet arrives on the interface, is captured before being blocked if a policy exist. We can see on the capture thre are syn flood send by the host, but we cannot see the reply from the web server (reply from port 80 to host destination port). If the server replies (sysn ack), It should be on the capture. We need to check on the server why there is no response. That's why we need to Run a sniffer on the web server (answer D).

Knowledge33
Sep 24, 2023

debug flow on the Fortigate will only help to confirm we do not receive anything from the server.

GCISystemIntegrator
Sep 28, 2023

Hi guys, by any chance can anyone tell me if all the examtopics nse4 questions are on the exam?

coolbacha
Mar 27, 2024

Answer is A and not D As we can see in the sniffer output that the sync requests are only comming to port 3 and not on port1 which means Fortigate is dropping the sync packet between port3 and port1 so this concludes that sync packets are not egressing from port1 towards the Server. so it makes no sense to run a Sniffer on the Web Server. Rather we run a Diagnose on Fortigate and try to find the reason for the packet drop between port3 and port1 hope this helps :)

TakumiOption: A
Jul 18, 2023

The answer is A

millerryOption: A
Jan 10, 2024

A. Executing a debug flow will help identify if packets are dropped due to firewall policies or security checks.

shobee
Mar 17, 2024

I can't see questions 105-109

e86cb90Option: A
Dec 6, 2023

Interface is set to any and is checking all traffic on port 80. The webserver is directly connected to the FortiGate. We would see traffic destined to port 80 with this sniffer. The only thing that makes sense is A.

Engrmunna
Dec 6, 2023

which answer should be used during the exam? suggested answer or the answer from Community vote distribution?

moldeadoraafrecho
Mar 26, 2024

Definitely read the community answers and the references they post, so you can conclude by your own the answer, it is the best approach

coolbachaOption: A
Mar 27, 2024

Answer is A