nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 86


Refer to the exhibits.

Exhibit A shows a network diagram. Exhibit B shows the firewall policy configuration and a VIP object configuration.

The WAN (port1) interface has the IP address 10.200.1.1/24.

The LAN (port3) interface has the IP address 10.0.1.254/24.

The administrator disabled the WebServer firewall policy.

Which IP address will be used to source NAT the traffic, if a user with address 10.0.1.10 connects over SSH to the host with address 10.200.3.1?

Show Answer
Correct Answer: C

The IP address that will be used to source NAT the traffic is 10.200.1.1. Since the traffic is coming from the LAN (10.0.1.10) to the WAN (10.200.3.1), and the WebServer firewall policy which includes the VIP (10.200.1.10 to 10.0.1.10) is disabled, the active Full_Access firewall policy is applied. This policy has NAT enabled, which means it will use the outgoing interface's IP address for NAT. Therefore, the outgoing IP will be the WAN interface IP address, which is 10.200.1.1.

Discussion

17 comments
Sign in to comment
GorgoyleOption: C
Aug 28, 2023

If WebServer firewall policy was active it would be A because: SNAT changes it to 10.200.1.10 due to VIP. But correct is C due to the disabled WebServer firewall policy. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-VIP-s-External-IP-Address-for-Source/ta-p/189947

raydel92
Sep 13, 2023

Even if WebServer firewall policy was active it would be C the correct answer. This traffic is coming from LAN to WAN, so match is in the first policy which has NAT enable so use outgoing interface IP address.

ccnax2Option: A
Jul 18, 2023

SNAT changes it to 10.200.1.10 due to VIP.

ccnax2
Jul 18, 2023

Disregard. Correct is C due to disabled the WebServer firewall policy.

MrSherman
Oct 19, 2023

Disabling the policy of the VIP does not deactivate the VIP. On a VIP called one-on-one or with no port forwarding assign. The external ip address will be used to snat the internal ip address. Try it on a lab.

DC095
Nov 17, 2023

The caveat is that there has to be an active firewall policy with the vip as the destination address object for the external vip to be used in SNAT as well.

Deep_Purple
Jul 27, 2023

You are correct. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-VIP-s-External-IP-Address-for-Source/ta-p/189947

alaaomar1985
Dec 17, 2023

The VIP entry must be referenced in at least one firewall policy in order to use VIP's external IP for performing SNAT.

RetroOption: C
Aug 22, 2023

NAT enabled will use outgoing interface address

kittituch01Option: C
Aug 23, 2023

C is correct

raydel92Option: C
Sep 13, 2023

C. 10.200.1.1 Traffic is coming from LAN to WAN, matches policy Full_Access which has NAT enable, so traffic uses source IP address of outgoing interface. Simple SNAT. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

rian00z_Option: A
Aug 20, 2023

Correct answer: A

raydel92Option: C
Sep 13, 2023

C. 10.200.1.1 Traffic is coming from LAN to WAN, matches policy Full_Access which has NAT enable, so traffic uses source IP address of outgoing interface. Simple SNAT. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

raydel92Option: C
Sep 13, 2023

C. 10.200.1.1 Traffic is coming from LAN to WAN, matches policy Full_Access which has NAT enable, so traffic uses source IP address of outgoing interface. Simple SNAT. Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html

e86cb90Option: C
Dec 5, 2023

VIPs are DNAT and this traffic is originating from LAN to WAN which would then use SNAT if enabled on the firewall policy.

yxpohOption: C
Dec 19, 2023

C Fortigate Security 7.2 Study Guide Pg 112 If policy with VIP is disabled, FG will not used it for SNAT purposes. Therefore the alternative would be the NAT rule used in Full_access, which since there’s no pool specified, it will be PAT which is the egress interface IP of 10.200.1.1.

AxiansPTOption: C
Feb 8, 2024

Fortigate Security 7.2 Study Guide Pg 112 If policy with VIP is disabled, FG will not used it for SNAT purposes.

MrShermanOption: A
Oct 19, 2023

10.0.1.10 has been natted with 10.200.1.10 as one-on-one nat. Disabling the VIP policy does not deactivate the VIP.

MrSherman
Oct 19, 2023

CORRECTION, C is the right one because the VIP policy is disabled.

SfelekaOption: C
Oct 22, 2023

c is the correct anser

Hummer1Option: C
Oct 27, 2023

The question is about SNAT so LAN to WAN rule, if traffic is destined from the LAN to WAN then it would NAT out over the WAN IP or if a IPPOOL was present it would NAT out over that. DNAT is inbound WAN to LAN so incoming traffic sent towards the VIP rule would be affected by the NAT. I think the correct answer is C.

MtoEOption: A
Nov 23, 2023

ChatGPT answer (XD): "Disabling a security policy on a Fortigate device will not deactivate the NAT VIP configured in it. The VIP will still translate traffic regardless of the policy being disabled. The security policy and NAT VIP are separate configurations on the Fortigate device, and disabling the security policy will not affect the operation of the NAT VIP"

alaaomar1985
Dec 17, 2023

The VIP entry must be referenced in at least one firewall policy in order to use VIP's external IP for performing SNAT.

alaaomar1985
Dec 17, 2023

The VIP entry must be referenced in at least one firewall policy in order to use VIP's external IP for performing SNAT.

GeniusAOption: C
Dec 26, 2023

C is a valid response