nse7_zta-72 Exam QuestionsBrowse all questions from this exam

nse7_zta-72 Exam - Question 17


An administrator wants to prevent direct host-to-host communication at layer 2 and use only FortiGate to inspect all the VLAN traffic.

What three things must the administrator configure on FortiGate to allow traffic between the hosts? (Choose three.)

Show Answer
Correct Answer: ABD

To prevent direct host-to-host communication at layer 2 and ensure all VLAN traffic is inspected by FortiGate, an administrator must block intra-VLAN traffic in the VLAN interface settings to prevent direct communication (A). Adding the VLAN interface to a software switch allows FortiGate to handle the traffic (B). Configuring a firewall policy is essential to allow the desired traffic to pass between hosts as all traffic will be routed through FortiGate (D). Static routes and proxy ARP are not necessary for this specific requirement.

Discussion

3 comments
Sign in to comment
E_NickOptions: ADE
Apr 3, 2024

Microsegmentation: Blocking intra-VLan traffic; Prevents Layer-2 connectivity between endpoints in the same VLan. All traffic passes through the FortiGate. When intra-VLan traffic is enabled, to allow traffic in the same VLan, you must enable a firewall policy and proxy-ARP on the FortiGate.

lil_pc1972Options: ADE
Mar 25, 2024

Microsegmentation: Blocking intra-VLan traffic; Prevents Layer-2 connectivity between endpoints in the same VLan. All traffic passes through the FortiGate. When intra-VLan traffic is enabled, to allow traffic in the same VLan, you must enable a firewall policy and proxy-ARP on the FortiGate.

Osirisdt89Options: ADE
Apr 30, 2024

Correct answer ADE