exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 13 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 13
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibits.
The exhibits contain a network diagram, and virtual IP, IP pool, and firewall policies configuration information.
The WAN (port1) interface has the IP address 10.200.1.1/24.
The LAN (port3) interface has the IP address 10.0.1.254/24.
The first firewall policy has NAT enabled using IP pool.
The second firewall policy is configured with a VIP as the destination address.


Which IP address will be used to source NAT (SNAT) the internet traffic coming from a workstation with the IP address 10.0.1.10?

  • A. 10.200.1.1
  • B. 10.0.1.254
  • C. 10.200.1.10
  • D. 10.200.1.100
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
1239944
Highly Voted 1 year, 3 months ago
Selected Answer: D
FortiOS 7.2 Study Guide Page 110: "(Step 2): FortiGate uses as NAT IP the external IP address defined in the VIP when performing SNAT on all egress traffic sourced from the mapped address in the VIP, provided the matching firewall policy has NAT enabled" "Note that you can override the behavior described in step 2 by using an IP pool"
upvoted 6 times
...
[Removed]
Highly Voted 1 year, 4 months ago
Selected Answer: C
Correct answer: C. 10.200.1.10. In the battle field, I observed this behavior related on article https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-VIP-s-External-IP-Address-for-Source/ta-p/189947?externalID=FD44529: - The second Firewall policy will activate the VIP so that its external IP address can be used to perform SNAT when the HOST generates traffic towards the Internet. - Internet Traffic from internal network will be allowed by first firewall policy for SNAT with VIP's external IP address.
upvoted 5 times
Mellon
5 months, 2 weeks ago
The Syslog server mode changed to udp, reliable, and legacy-reliable. You must set the mode to reliable to support extended logging,
upvoted 1 times
...
spydog
1 year, 3 months ago
That is correct when outbound traffic is matching rule with SNAT using egress interface. When SNAT is configured to use IP Pool, this will override the VIP IP external address.
upvoted 1 times
...
...
davidmdlp85
Most Recent 1 month, 3 weeks ago
Selected Answer: C
taken from the study guide: The default VIP type is Static NAT. This is a one-to-one mapping. This means that: 1. FortiGate performs DNAT on ingress traffic destined to the external IP address defined in the VIP, regardless of the protocol and port of the connection, provided the matching firewall policy references the VIP as Destination. 2. FortiGate uses as NAT IP the external IP address defined in the VIP when performing SNAT on all egress traffic sourced from the mapped address in the VIP, provided the matching firewall policy has NAT enabled. That is, FortiGate doesn’t use the egress interface address as NAT IP.
upvoted 1 times
...
davidmdlp85
2 months ago
Selected Answer: C
Should be C the study guides have an example like this Now, suppose that the internal web server (172.16.1.10) initiates a DNS connection to the internet DNS server (4.2.2.2). On FortiGate, the traffic matches the firewall policy ID 2, which has nat enabled. Because the source address matches the internal address of the VIP, and because the VIP is configured as static NAT with port forwarding disabled, FortiGate translates the source address of the packet to 70.70.70.71 from 172.16.1.10. Note that FortiGate doesn’t have to perform PAT because the static NAT VIP equals one-to one mapping. That is, the external IP is used by the web server only for SNAT
upvoted 1 times
...
LiilGenius
5 months, 3 weeks ago
Selected Answer: D
D. 10.200.1.100
upvoted 1 times
...
GopiChandMurari
9 months, 1 week ago
C The VIP configured with static NAT takes precedence over the NAT overload (PAT) of the IP pool.
upvoted 2 times
...
kev91
9 months, 1 week ago
D. 10.200.1.100
upvoted 1 times
...
AMK2ENG
1 year ago
D. 10.200.1.100
upvoted 1 times
...
GeniusA
1 year ago
Option D is the correct answer
upvoted 1 times
...
Ygrec
1 year, 2 months ago
Selected Answer: D
D Because it uses the IP POOL range from LAN to WAN
upvoted 3 times
...
itzuy06
1 year, 3 months ago
Selected Answer: D
D. 10.200.1.100
upvoted 2 times
...
raydel92
1 year, 4 months ago
Selected Answer: D
D. 10.200.1.100 Reference and download study guide: https://ebin.pub/fortinet-fortigate-security-study-guide-for-fortios-72.html
upvoted 2 times
...
Garry_G
1 year, 4 months ago
I know that in some situations, the VIP IP is used for SNAT, but are never sure what the requirements are for that to happen ... :( I tried the setup on our live system, but the firewall kept using the NAT pool instead of the VIP NAT
upvoted 1 times
spydog
1 year, 3 months ago
VIP external IP will be used for source NAT for outbound traffic, when traffic is matching policy enabled with NAT for egress interface. If outbound traffic match rule with NAT enabled and IP pool configured. Traffic will use the IP pool external IP. Basically SNAT priority from high to low will be : 1) IP pool 2) VIP IP 3) SNAT egress interface
upvoted 5 times
...
...
Slash_JM
1 year, 4 months ago
Selected Answer: D
FortiGate Security 7.2 Study Guide p.97-98
upvoted 2 times
...
Mboweni
1 year, 7 months ago
D is the correct answer
upvoted 1 times
...
Danny_B
1 year, 7 months ago
Selected Answer: D
7.2 SEC 97-98
upvoted 1 times
...
fc8
1 year, 8 months ago
https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-VIP-s-External-IP-Address-for-Source/ta-p/189947?externalID=FD44529
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago