exam questions

Exam NSE4_FGT-6.4 All Questions

View all questions & answers for the NSE4_FGT-6.4 exam

Exam NSE4_FGT-6.4 topic 1 question 42 discussion

Actual exam question from Fortinet's NSE4_FGT-6.4
Question #: 42
Topic #: 1
[All NSE4_FGT-6.4 Questions]

Consider the topology:
Application on a Windows machine <--{SSL VPN} -->FGT--> Telnet to Linux server.
An administrator is investigating a problem where an application establishes a Telnet session to a Linux server over the SSL VPN through FortiGate and the idle session times out after about 90 minutes. The administrator would like to increase or disable this timeout.
The administrator has already verified that the issue is not caused by the application or Linux server. This issue does not happen when the application establishes a Telnet connection to the Linux server directly on the LAN.
What two changes can the administrator make to resolve the issue without affecting services running through FortiGate? (Choose two.)

  • A. Set the maximum session TTL value for the TELNET service object.
  • B. Set the session TTL on the SSLVPN policy to maximum, so the idle session timeout will not happen after 90 minutes.
  • C. Create a new service object for TELNET and set the maximum session TTL.
  • D. Create a new firewall policy and place it above the existing SSLVPN policy for the SSL VPN traffic, and set the new TELNET service object in the policy.
Show Suggested Answer Hide Answer
Suggested Answer: CD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aads
Highly Voted 3 years, 11 months ago
The key here is performing the task without affecting any of the other services. - Not A - Changing the maximum TTL value for TELNET will affect every other policy that references the TELNET service - Not B - Changing the session TTL on the SSLVPN policy will impact other services referenced in the policy. Hence the answer is C and D
upvoted 40 times
Biz90
3 years, 11 months ago
aads, awesome work! I was sitting here for a good 15 minutes thinking those answers are wrong, and trying think why! I agree C and D are correct
upvoted 3 times
...
...
Ibrahimadwan
Most Recent 1 year, 11 months ago
C & D is correct
upvoted 1 times
...
cierzo
2 years, 8 months ago
Selected Answer: CD
C & D is correct
upvoted 1 times
...
ibos8383
3 years ago
Selected Answer: CD
the answer is c and d
upvoted 1 times
...
hippo2048
3 years, 1 month ago
Selected Answer: CD
agree with aads
upvoted 2 times
...
mario156090
3 years, 1 month ago
C and D is the answer.
upvoted 2 times
...
yaboi01
3 years, 3 months ago
how do you change the TTL on a service object???
upvoted 1 times
SandroAlex
3 years ago
In CLI, config firewall service custom
upvoted 1 times
...
...
Flo31
3 years, 3 months ago
Selected Answer: CD
C & D is correct
upvoted 1 times
...
forti_Ctes
3 years, 7 months ago
c & D correct
upvoted 1 times
...
5pik3
3 years, 7 months ago
c & d. No doubt.
upvoted 1 times
...
mrigen888
3 years, 8 months ago
c and d is correct
upvoted 1 times
...
salon442
3 years, 10 months ago
c and d is correct
upvoted 1 times
...
salon442
3 years, 11 months ago
yeah c and d is correct
upvoted 1 times
...
darkMmve
4 years ago
A and B are correct. Under service objects you can do set session-TTL 0 or just increase it
upvoted 2 times
francis57
3 years, 11 months ago
A is wrong as we have "without affecting services running through FortiGate". So we need to create a new service and put it to this rule only.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago