nse4_fgt-72 Exam QuestionsBrowse all questions from this exam

nse4_fgt-72 Exam - Question 3


FortiGate is operating in NAT mode and is configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface.

In this scenario, what are two requirements for the VLAN ID? (Choose two.)

Show Answer
Correct Answer: CD

The two VLAN subinterfaces must have different VLAN IDs to ensure each VLAN is uniquely identified and traffic is properly segregated. Additionally, the two VLAN subinterfaces can have the same VLAN ID only if they have IP addresses in different subnets, allowing them to operate without IP address conflicts while still maintaining separate network segments.

Discussion

17 comments
Sign in to comment
Garry_GOptions: CD
Apr 18, 2023

Anything but the "different VLAN" answer is impossible from a networking view, as well as configuration on the FG is concerned. At least up to 7.0 it's impossible to configure the same VLAN on the same physical link multiple times, no matter if it's in separate VDOMs or not.

Garry_G
Sep 5, 2023

P.S. - did some tests - at least up to 7.0.12, the firewall will instantly complain about duplicate VLAN ID no matter if you select different VDOMs, IPs, or IPs from the same subnet (which will ADDITIONALLY cause an IP-conflict with the first VLAN interface) So, if the official test has this question and asks for two choices, it's definitely wrong ... (as any sane technician would argue)

Bungee75
Jun 20, 2024

t is C and D. But to achieve this monstrosity you have to implement 802.1Q and 802.1AD vlans and they need to be in different subnets. And yes this is still mind boggling.

erawemkOptions: CD
Jul 4, 2023

I used my own lab to resolve this question: If you use the same VLAN ID to add a second subinterface to the same physical interface is not allowed you get the error ( VLAN ID used by another VLAN switch) unless you change the VLAN Protocol to 802.1AD, no matter the VDOM you assign the subinterface. Being said that, options A and B are not true, the option C is correct and option D is true if as I said before you use 802.1Q in one subinterface and 802.1AD in the second subinterface.

BosubwOptions: CD
Mar 24, 2024

Tested in lab, vdom is not significant. Only option is to use 802.1Q and 802.1AD with different subnet

Knowledge33Options: BC
Oct 21, 2023

b and c

nazarethOptions: BC
Oct 23, 2023

b and c

keshzyOptions: BC
Oct 23, 2023

VLANs split your physical LAN into multiple, logical LANs. In NAT operation mode, each VLAN forms a separate broadcast domain. Multiple VLANs can coexist in the same physical interface, provided they have different VLAN IDs. In this way, a physical interface is split into two or more logical interfaces. A tag is added to each Ethernet frame to identify the VLAN to which it belongs. Note that in a multi-VDOM environment, the physical interface and its VLAN sub-interface can be in separate VDOMs.

Diego_FaraniOptions: BC
Nov 14, 2023

Basic concept of VLAN.

TheManDudeOption: C
Nov 25, 2023

This Question has been asked on 7.0 and 6.4 NSE 4. It’s always been a one answer question. So it’s only C.

GeniusAOptions: BC
Dec 19, 2023

B & C is the correct answer

znznzn219Options: BC
Jan 15, 2024

Correct

GoodServantOptions: BC
Mar 23, 2024

C is definitely true as everyone has already mentioned. B and D are also true if you change one of the interfaces to use 802.1AD.

MAUROBTAOptions: BC
Mar 25, 2024

Las correctas con B y C

MAUROBTAOptions: BC
Mar 25, 2024

Las correctas son la B y C

GopiChandMurariOptions: CD
May 13, 2024

c,D In a scenario where FortiGate is operating in NAT mode and configured with two virtual LAN (VLAN) subinterfaces added to the same physical interface, the correct requirements for the VLAN ID are: C. **The two VLAN subinterfaces must have different VLAN IDs.** Each VLAN subinterface should have a unique VLAN ID to properly segregate traffic between VLANs. D. **The two VLAN subinterfaces can have the same VLAN ID, only if they have IP addresses in different subnets.** If two VLAN subinterfaces share the same VLAN ID, they must belong to different IP subnets to avoid IP address conflicts and ensure proper routing of traffic. So, options C and D are the correct requirements for the VLAN ID in this scenario.

learner2024Options: CD
May 16, 2024

C is correct but not sure about the other, this questions seems like wrong to me it has single answer only

GasimovTofig
May 22, 2024

Anybody got in Exam newly? Are those questions legit still?

AJMDOptions: CD
Jun 4, 2024

C and D