B and D
about D. https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-Reverse-Path-Forwarding-RPF-per/ta-p/193338
and between B and C take a look here : https://community.fortinet.com/t5/FortiGate/Technical-Note-Reverse-Path-Forwarding-RPF-implementation-and/ta-p/194382
C is not enough as you have to add a supernet route as "feasible patch" or + adding the same route as the best matching one (same subnet, same prefix, same distance) but having a higher priority value than the best match one. This will force the route to be injected in the routing table as a second choice.
B and D correct: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-Reverse-Path-Forwarding-RPF-per/ta-p/193338
disable strict-src-check change the RPF mode to feasible path, but does not disable RPF
B is correct, because to disable RPF at interface level you use:
config system interface
edit <interface>
set src-check disable
end
In other words, one thing is strict-src-check at system level and there is src-check at interfase level.
FortiGate_Infrastructure_7.0_Study_Guide-Online – page 39
enable asymmetric routing and disable checking at the interface level ...reduces security of your network
"You can disable RPF checking in two ways. If you enable asymmetric routing, it disables RPF checking system wide. However this reduces the security of your network. Features, such as antivirus and IPS become noneffective. So, if you need to disable RPF checking, you can do so at the interface level using the commands shown on this slide (set asymroute enable & set src-check disable @ interface)
upvoted 12 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
LaScarD
1 month, 1 week agoMahant55
3 months, 1 week agoSelvapraba15
5 months agoKirey
6 months, 4 weeks agoTimbal
7 months agoeinstein85
9 months, 2 weeks agoBUZOMD
10 months agozeebo340
10 months, 1 week agohamidreza0010
10 months, 4 weeks agoKutchek
1 year, 3 months agoFebrian
1 year, 4 months agoKutchek
1 year, 3 months ago